LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workaround this issue, set suricata.yaml app-layer.protocols.http.libhtp.default-config.lzma-enabled to false. This issue is fixed in version 0.5.51.
{
"cwe_ids": [
"CWE-401"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53537.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.5.51"
}
]
}"2026-07-22T04:02:15Z"
[
{
"signature_type": "Function",
"target": {
"file": "htp/htp_decompressors.c",
"function": "htp_gzip_decompressor_decompress"
},
"deprecated": false,
"source": "https://github.com/oisf/libhtp/commit/9037ea35110a0d97be5cedf8d31fb4cd9a38c7a7",
"id": "CVE-2025-53537-3b8b509d",
"signature_version": "v1",
"digest": {
"function_hash": "319711909622117197521685987553061998773",
"length": 5133.0
}
},
{
"signature_type": "Line",
"target": {
"file": "htp/htp_decompressors.c"
},
"deprecated": false,
"source": "https://github.com/oisf/libhtp/commit/9037ea35110a0d97be5cedf8d31fb4cd9a38c7a7",
"id": "CVE-2025-53537-6b016fe0",
"signature_version": "v1",
"digest": {
"line_hashes": [
"314874631301158083186356419889154641168",
"243774011686098355107542034887210145255",
"319072459999517054393152480369356483307",
"314663555217702912454495326075304104788"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53537.json"