CVE-2026-22263
5.3
MEDIUM
CVSS 3.1
EPSS 0.03%
Description
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.
How to fix CVE-2026-22263
To remediate CVE-2026-22263, upgrade the affected package to a fixed version below.
- Debian/suricata—upgrade to 1:8.0.3-1 or later
Is CVE-2026-22263 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:8.0.3-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |