Allocation of Resources Without Limits or Throttling in Suricata - #VU152932
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Suricata's per-thread decision cache when processing high-cardinality traffic matching IPv4 signatures configured with source- or destination-tracked limit or both thresholds. A remote attacker can send high-cardinality traffic to exhaust memory and terminate Suricata.
In inline deployments, traffic forwarding may be interrupted.