Numeric Truncation Error in Suricata - CVE-2026-63449
Published: July 22, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to evade detection of SIP message body content.
The vulnerability exists due to numeric truncation error in the SIP parser when processing SIP messages with bodies larger than 65536 bytes. A remote attacker can send a specially crafted SIP message to evade detection of SIP message body content.
The issue affects inspection using the frame:request.body or frame:response.body keywords because the full body content is not included.