CVE-2019-17420: Oisf Libhtp
Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
Affected products
- Oisf Libhtp: before 0.5.31 (fixed in 0.5.31)
- Suricata-Ids Suricata: version 4.1.4 only
Published 2019-10-10. Last modified 2026-06-17.