Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default.
| Software | From | Fixed in |
|---|---|---|
| oisf / suricata | - | 7.0.14 |
| oisf / suricata | 8.0.0 | 8.0.3 |