Oisf Suricata vulnerabilities
100 known vulnerabilities affecting oisf/suricata.
Total CVEs
100
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH67MEDIUM19LOW1
Vulnerabilities
Page 4 of 5
CVE-2025-64334P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.2v>= 8.0.0, < 8.0.22025-11-26
CVE-2025-64334 [HIGH] CWE-770 CVE-2025-64334: Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Found
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or
nvdosv
CVE-2024-47187P3HIGHCVSS 7.5fixed in 7.0.72024-10-16
CVE-2024-47187 [HIGH] CWE-330 CVE-2024-47187: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance
nvdosv
CVE-2026-31934P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.4v>= 8.0.0, < 8.0.42026-04-02
CVE-2026-31934 [HIGH] CWE-407 CVE-2026-31934: Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.
nvdosv
CVE-2026-45747P3HIGHCVSS 7.5fixed in 7.0.162026-09-10
CVE-2026-45747 [HIGH] CWE-476 CVE-2026-45747: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS tr
nvd
CVE-2026-45759P3HIGHCVSS 7.5fixed in 7.0.16v>= 8.0.0, < 8.0.52026-09-10
CVE-2026-45759 [HIGH] CWE-400 CVE-2026-45759: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposition` headers during HTTP response body processing. Crafted HTTP traffic could cause excessive CPU usage and denial o
nvd
CVE-2019-10050P3HIGHCVSS 7.5≥ 4.0.0, < 4.1.42019-05-13
CVE-2019-10050 [HIGH] CWE-125 CVE-2019-10050: A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-m
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type field and the right number for shim, an attacker can manipulate the control flow, such that the condition to leave the loop is true. A
nvdosv
CVE-2024-23835P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.3v>= 7.0.0, <= 7.0.22024-02-26
CVE-2024-23835 [HIGH] CWE-400 CVE-2024-23835: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser.
nvdosv
CVE-2025-59150P3HIGHCVSS 7.5v8.0.0v>= 8.0.0, < 8.0.12025-10-01
CVE-2025-59150 [HIGH] CWE-476 CVE-2025-59150: Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Found
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead to a segmentation fault when the decoded subjectaltname contains a NULL byte. This issue is fixed in version 8.0.1. To workaround this issue, disable rul
nvd
CVE-2026-45765P3HIGHCVSS 7.5v>= 8.0.0, < 8.0.5fixed in 7.0.162026-09-10
CVE-2026-45765 [HIGH] CWE-400 CVE-2026-45765: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted DNP3 traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0
nvd
CVE-2018-10242P3HIGHCVSS 7.5v4.0.42019-04-04
CVE-2018-10242 [HIGH] CWE-125 CVE-2018-10242: Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
nvdosv
CVE-2019-1010279P3HIGHCVSS 7.5fixed in 4.1.32019-07-18
CVE-2019-1010279 [HIGH] CWE-347 CVE-2019-1010279: Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Servi
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequence of network packets. The component is: detect.c (https://github.com/OISF/suricata/pull/3625/commits/d8634daf74c882356659addb65f
nvdosv
CVE-2024-38536P3HIGHCVSS 7.5fixed in 7.0.62024-07-11
CVE-2024-38536 [HIGH] CWE-476 CVE-2024-38536: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
nvdosv
CVE-2024-55628P3HIGHCVSS 7.5fixed in 7.0.82025-01-06
CVE-2024-55628 [HIGH] CWE-405 CVE-2024-55628: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log records. While there are limits in place, they were too
nvdosv
CVE-2026-45766P3HIGHCVSS 7.5v>= 8.0.0, < 8.0.5fixed in 7.0.162026-09-10
CVE-2026-45766 [HIGH] CWE-400 CVE-2026-45766: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.
nvd
CVE-2019-10051P3HIGHCVSS 7.5≥ 0, < 1:4.1.4-12019-08-28
CVE-2019-10051 [HIGH] CVE-2019-10051: An issue was discovered in Suricata 4
An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs error condition and crashes.
osv
CVE-2017-15377P3HIGHCVSS 7.5≥ 0, < 1:4.0.0-12017-10-23
CVE-2017-15377 [HIGH] CVE-2017-15377: In Suricata before 4
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn't stop when it should after no match is found; instead, it stops only upon reaching inspection-recursion-limit (3000 by default).
osv
CVE-2019-10054P3HIGHCVSS 7.5≥ 0, < 1:4.1.4-12019-08-28
CVE-2019-10054 [HIGH] CVE-2019-10054: An issue was discovered in Suricata 4
An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nfs3.rs file.
osv
CVE-2019-10056P3HIGHCVSS 7.5≥ 0, < 1:4.1.4-12019-08-28
CVE-2019-10056 [HIGH] CVE-2019-10056: An issue was discovered in Suricata 4
An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function DecodeEthernet in decode-ethernet.c is executed a second time. At this point, the algorithm cuts the first part of the packet and doesn't determine the current length. Specifically, if the packet is exactly 28 long, in the first iteration it subtracts 14 bytes. Then, it is workin
osv
CVE-2019-10055P3HIGHCVSS 7.5≥ 0, < 1:4.1.4-12019-08-28
CVE-2019-10055 [HIGH] CVE-2019-10055: An issue was discovered in Suricata 4
An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.
osv
CVE-2015-0928P4HIGHCVSS 7.5≥ 0, < 2.0.7-12017-08-28
CVE-2015-0928 [HIGH] CVE-2015-0928: libhtp 0
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
osv