CVE detail
CVE-2024-23839 — CVE-2024-23839
Published 2024-02-26 · Modified 2026-06-17 · Vendor oisf · Product suricata · Source nvd
HIGH
severity
CVSS-derived band
0.0078
EPSS probability
exploitation probability, 30d
53.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References