We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53537

LibHTP's memory leak with lzma can lead to resource starvation



Description

LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workaround this issue, set `suricata.yaml app-layer.protocols.http.libhtp.default-config.lzma-enabled` to false. This issue is fixed in version 0.5.51.

Reserved 2025-07-02 | Published 2025-07-23 | Updated 2025-07-23 | Assigner GitHub_M


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-401: Missing Release of Memory after Effective Lifetime

Product status

< 0.5.51
affected

References

github.com/...libhtp/security/advisories/GHSA-v3qq-h8mh-vph7

github.com/...ommit/9037ea35110a0d97be5cedf8d31fb4cd9a38c7a7

cve.org (CVE-2025-53537)

nvd.nist.gov (CVE-2025-53537)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53537

Support options

Helpdesk Chat, Email, Knowledgebase