CVE-2026-63449

Summary

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes can truncate the length and prevent frame:request.body or frame:response.body from exposing the complete body to inspection, allowing content in the omitted portion to evade frame-based detection. This issue is fixed in version 8.0.6.

Affected Software

VendorProductVersion RangeStatus
OISFsuricata>= 8.0.0, < 8.0.6affected

Weaknesses

  • CWE-197: CWE-197: Numeric Truncation Error

References