cbcvebase.

Oisf Suricata vulnerabilities

100 known vulnerabilities affecting oisf/suricata.

Total CVEs
100
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH67MEDIUM19LOW1

Vulnerabilities

Page 5 of 5
CVE-2017-7177P4HIGHCVSS 7.5≥ 0, < 3.2.1-12017-03-18
CVE-2017-7177 [HIGH] CVE-2017-7177: Suricata before 3 Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
osv
CVE-2026-45751P4MEDIUMCVSS 5.9fixed in 7.0.16v>= 8.0.0, < 8.0.52026-09-10
CVE-2026-45751 [MEDIUM] CWE-416 CVE-2026-45751: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could leave an inspection pointer referencing freed memory after a chained transform caused the backing buffer to be reallocated. The issue is reached during a s
nvd
CVE-2026-45763P4MEDIUMCVSS 5.9v>= 8.0.0, < 8.0.52026-09-10
CVE-2026-45763 [MEDIUM] CWE-770 CVE-2026-45763: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory limit was not consistently enforced for new allocations. Certain Lua allocation patterns could exceed `security.lua.max-
nvd
CVE-2026-22263P4MEDIUMCVSS 5.3≥ 8.0.0, < 8.0.3v>= 8.0.0, < 8.0.32026-01-27
CVE-2026-22263 [MEDIUM] CWE-1050 CVE-2026-22263: Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.
nvdosv
CVE-2026-22261P4MEDIUMCVSS 5.3fixed in 7.0.14≥ 8.0.0, < 8.0.3+1 more2026-01-27
CVE-2026-22261 [MEDIUM] CWE-1050 CVE-2026-22261: Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficie Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default.
nvdosv
CVE-2026-45752P4MEDIUMCVSS 5.9v>= 8.0.0, < 8.0.52026-09-10
CVE-2026-45752 [MEDIUM] CWE-416 CVE-2026-45752: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when certain detection transforms are chained, the decompress transform pipeline could read from an inspection buffer after it had been reallocated and freed. The issue is reached
nvd
CVE-2024-32867P4MEDIUMCVSS 5.3≥ 6.0.0, < 6.0.19≥ 7.0.0, < 7.0.5+2 more2024-05-07
CVE-2024-32867 [MEDIUM] CWE-754 CVE-2024-32867: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
nvdosv
CVE-2024-24568P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.3v>= 7.0.0, < 7.0.32024-02-26
CVE-2024-24568 [MEDIUM] CWE-284 CVE-2024-24568: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.
nvdosv
CVE-2025-59149P4MEDIUMCVSS 6.2v8.0.0v>= 8.0.0, < 8.0.12025-10-01
CVE-2025-59149 [MEDIUM] CWE-121 CVE-2025-59149: Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Found Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or during a rule reload. This issue is fixed in version
nvd
CVE-2016-10728P4MEDIUMCVSS 5.3≥ 0, < 3.1.2-12018-07-23
CVE-2016-10728 [MEDIUM] CVE-2016-10728: An issue was discovered in Suricata before 3 An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
osv
CVE-2024-45796P4MEDIUMCVSS 5.3fixed in 7.0.72024-10-16
CVE-2024-45796 [MEDIUM] CWE-193 CVE-2024-45796: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, a logic error during fragment reassembly can lead to failed reassembly for valid traffic. An attacker could craft packets to trigger this behavior.This issue has been addressed in 7.0.7.
nvdosv
CVE-2026-45767P4MEDIUMCVSS 4.4v>= 8.0.0, < 8.0.5fixed in 7.0.162026-09-10
CVE-2026-45767 [MEDIUM] CWE-22 CVE-2026-45767: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Preprocess `load`+ `save` ru
nvd
CVE-2014-6603P4MEDIUMCVSS 5.0≥ 0, < 2.0.4-12014-10-07
CVE-2014-6603 [MEDIUM] CVE-2014-6603: The SSHParseBanner function in SSH parser (app-layer-ssh The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
osv
CVE-2025-29918P4MEDIUMCVSS 5.5fixed in 7.0.92025-04-10
CVE-2025-29918 [MEDIUM] CWE-835 CVE-2025-29918: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite loop limiting visibility and availability in inline mode. This vulnerability is fixed in 7.0.9.
nvdosv
CVE-2025-29917P4MEDIUMCVSS 5.5fixed in 7.0.92025-04-10
CVE-2025-29917 [MEDIUM] CWE-770 CVE-2025-29917: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly limited. Due to this, signatures using the keyword and setting can cause large memory allocations of up to 4 GiB per thread. This vulnerability is fixed in 7.0.9.
nvdosv
CVE-2025-29916P4MEDIUMCVSS 5.5fixed in 7.0.92025-04-10
CVE-2025-29916 [MEDIUM] CWE-770 CVE-2025-29916: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table allocation can be large. Untrusted rules can lead to large memory allocations, potentially leadin
nvdosv
CVE-2024-55626P4MEDIUMCVSS 5.5fixed in 7.0.82025-01-06
CVE-2024-55626 [MEDIUM] CWE-680 CVE-2024-55626: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.
nvdosv
CVE-2013-5919P4MEDIUMCVSS 5.0v1.3v1.3.1+10 more2014-05-30
CVE-2013-5919 [MEDIUM] CWE-20 CVE-2013-5919: Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed S Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
nvdosv
CVE-2015-0971P4MEDIUMCVSS 5.0≥ 0, < 2.0.8-12015-05-14
CVE-2015-0971 [MEDIUM] CVE-2015-0971: The DER parser in Suricata before 2 The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.
osv
CVE-2026-45761P4LOWCVSS 3.3v>= 8.0.0, < 8.0.5fixed in 7.0.162026-09-10
CVE-2026-45761 [LOW] CWE-122 CVE-2026-45761: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow while Suricata is loading signatures. The issue is reached during rule parsing/loading rather than by network traffic
nvd
Oisf Suricata vulnerabilities | cvebase