CVE-2025-64334

Source
https://cve.org/CVERecord?id=CVE-2025-64334
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64334.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64334
Aliases
  • GHSA-r5jf-v2gx-gx8w
Downstream
Related
Published
2025-11-26T22:39:15.552Z
Modified
2026-03-23T05:11:43.185379640Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Suricata is vulnerable to unbounded memory growth for decompression
Details

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64334.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-770"
    ]
}
References

Affected packages

Git / github.com/oisf/suricata

Affected ranges

Type
GIT
Repo
https://github.com/oisf/suricata
Events

Affected versions

suricata-8.*
suricata-8.0.0
suricata-8.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64334.json"