LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workaround this issue, set suricata.yaml app-layer.protocols.http.libhtp.default-config.lzma-enabled to false. This issue is fixed in version 0.5.51.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-401"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53537.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.5.51"
}
],
"cpe": "cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
[
{
"target": {
"function": "htp_gzip_decompressor_decompress",
"file": "htp/htp_decompressors.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/oisf/libhtp/commit/9037ea35110a0d97be5cedf8d31fb4cd9a38c7a7",
"digest": {
"function_hash": "319711909622117197521685987553061998773",
"length": 5133.0
},
"id": "CVE-2025-53537-3b8b509d"
},
{
"target": {
"file": "htp/htp_decompressors.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/oisf/libhtp/commit/9037ea35110a0d97be5cedf8d31fb4cd9a38c7a7",
"digest": {
"threshold": 0.9,
"line_hashes": [
"314874631301158083186356419889154641168",
"243774011686098355107542034887210145255",
"319072459999517054393152480369356483307",
"314663555217702912454495326075304104788"
]
},
"id": "CVE-2025-53537-6b016fe0"
}
]
"2026-08-12T15:13:59Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53537.json"