PT-2025-29085 · Libhtp+4 · Libhtp+4
Jasonish
·
Published
2025-07-10
·
Updated
2025-12-02
·
CVE-2025-53537
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
LibHTP versions 0.5.50 and below
Description
LibHTP is a security-aware parser for the HTTP protocol. Versions 0.5.50 and below contain a traffic-induced memory leak that can lead to process memory starvation and loss of visibility.
Recommendations
Set
suricata.yaml app-layer.protocols.http.libhtp.default-config.lzma-enabled to false.
Update to version 0.5.51.Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Libhtp
Linuxmint
Ubuntu