Sploitus

CVE-2025-53538

No indexed exploits for CVE-2025-53538 yet

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.0.10 and below and 8.0.0-beta1 through 8.0.0-rc1, mishandling of data on HTTP2 stream 0 can lead to uncontrolled memory usage, leading to loss of visibility. Workarounds include disabling the HTTP/2 parser, and using a signature like drop http2 any any -> any any (frame:http2.hdr; byte_test:1,=,0,3; byte_test:4,=,0,5; sid: 1;) where the first byte test tests the HTTP2 frame type DATA and the second tests the stream id 0. This is fixed in versions 7.0.11 and 8.0.0.

Affected products
Alt Linux, Debian, Suricata
Oisf Suricata
< 7.0.11, 8.0.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.4% (36th percentile)
Weakness
CWE-400, CWE-770
NVD status
Analyzed
Published
2025-07-22
CVE-2025-53538 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-53538 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-53538 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.