CVE Alert: CVE-2025-53538

Vulnerability Summary: CVE-2025-53538
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.0.10 and below and 8.0.0-beta1 through 8.0.0-rc1, mishandling of data on HTTP2 stream 0 can lead to uncontrolled memory usage, leading to loss of visibility. Workarounds include disabling the HTTP/2 parser, and using a signature like drop http2 any any -> any any (frame:http2.hdr; byte_test:1,=,0,3; byte_test:4,=,0,5; sid: 1;) where the first byte test tests the HTTP2 frame type DATA and the second tests the stream id 0. This is fixed in versions 7.0.11 and 8.0.0.
Affected Endpoints:
No affected endpoints listed.
Published Date:
7/22/2025, 10:15:37 PM
🔥 CVSS Score:
Exploit Status:
Not ExploitedReferences:
- https://github.com/OISF/suricata/commit/1d6d331752e933c46aca0ae7a9679b27462246e3
- https://github.com/OISF/suricata/commit/7fa88ea9e7d05e07a7864050cfd836b576669720
- https://github.com/OISF/suricata/security/advisories/GHSA-qrr7-crgj-cmh3
Recommended Action:
No proposed action available. Please refer to vendor documentation for updates.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.