Inefficient Algorithmic Complexity in Suricata - CVE-2026-71418
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the DNS-over-HTTP/2 handling when processing crafted HTTP/2 DATA frames with the EndOfStream flag set. A remote attacker can send crafted DoH2 traffic containing multiple DATA frames to cause a denial of service.
The issue can degrade packet processing and potentially cause loss of monitoring visibility.