Suricata is a network IDS, IPS and NSM engine
Description
Suricata is a network IDS, IPS and NSM engine
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
22 high and critical vulnerabilities covered by CVE Brief since 2025-07-23, each with independent analyst commentary.
← All vendors20 CVEs in the last 12 months
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
A high-severity flaw in the Suricata engine could compromise the reliability of network intrusion detection and prevention.
Executive Summary:
The Suricata network IDS/IPS engine is vulnerable to an exploit that could lead to engine failure or the evasion of security controls.
Vulnerability Details
CVE-ID: CVE-2026-31935
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability affects the Suricata engine's ability to process network traffic correctly. An unauthenticated remote attacker could exploit this flaw to cause a denial of service or to bypass the security signatures intended to protect the network.
Business Impact
The compromise of a network security engine like Suricata can result in a complete loss of visibility into malicious network activity. Given the CVSS score of 7.5, the risk of a successful attack is high, potentially leading to long-term undetected access by adversaries and significant remediation costs.
Remediation Plan
Immediate Action: Apply the recommended security patches for Suricata as soon as they are made available by the vendor or distribution.
Proactive Monitoring: Regularly audit the Suricata configuration and performance metrics to ensure the engine is operating at full capacity and without errors.
Compensating Controls: Deploy additional network-level security measures, such as access control lists (ACLs) on routers, to provide a baseline level of protection.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. The complexity of modern network traffic makes engine-level vulnerabilities a constant threat.
Analyst Recommendation
Apply the primary remediation patch immediately. Ensuring the continued operation and integrity of the IDS/IPS infrastructure is paramount to maintaining an effective security posture against modern threats.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
A vulnerability in Suricata's network engine could allow an attacker to bypass intrusion detection signatures or crash the inspection service.
Executive Summary:
Suricata, a critical network security engine, contains a high-severity vulnerability that could be exploited to disable or evade network monitoring.
Vulnerability Details
CVE-ID: CVE-2026-31934
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This flaw exists in the Suricata network IDS/IPS engine. It allows an unauthenticated attacker to potentially bypass security rules or cause a denial-of-service condition by sending malformed or specifically sequenced network traffic to the affected sensor.
Business Impact
With a CVSS score of 7.5, this vulnerability represents a significant threat to network security operations. An effective exploit could disable the organization's "first line of defense," leading to increased risk of undetected breaches, intellectual property theft, and non-compliance with security standards.
Remediation Plan
Immediate Action: Upgrade the Suricata engine to the most recent version provided by the vendor to close the identified security gap.
Proactive Monitoring: Enable detailed logging for the Suricata engine to capture evidence of potential exploitation attempts or malformed packet processing errors.
Compensating Controls: Utilize a multi-vendor security strategy where possible to ensure that a single point of failure in one IDS engine does not leave the network entirely unprotected.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, the high severity and potential for IDS evasion make this a critical issue for security teams.
Analyst Recommendation
Immediate remediation via patching is strongly advised. Organizations should treat this as a high-priority update to ensure that their network monitoring capabilities are not compromised by external actors.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
The Suricata engine is vulnerable to a flaw that could result in a denial of service or the bypass of network security policies.
Executive Summary:
Suricata network security sensors are affected by a high-severity vulnerability that could compromise the integrity of network traffic inspection.
Vulnerability Details
CVE-ID: CVE-2026-31933
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability resides within the Suricata engine, which functions as a network IDS and IPS. An unauthenticated attacker may be able to trigger this flaw by sending specific network packets, potentially leading to a crash of the Suricata process or a failure to inspect certain traffic.
Business Impact
A CVSS score of 7.5 indicates a high severity level, as this flaw directly undermines the primary defensive mechanism for the network. A successful exploit could lead to unauthorized network access going unnoticed, resulting in data exfiltration, malware propagation, or significant operational disruptions.
Remediation Plan
Immediate Action: Update all Suricata installations to the latest patched version available from the vendor.
Proactive Monitoring: Implement external monitoring for the Suricata service status to detect and respond to any engine crashes in real-time.
Compensating Controls: Ensure that secondary security controls, such as NetFlow analysis, are active to provide visibility if the primary IDS fails.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. Security researchers frequently target IDS engines, increasing the likelihood of an exploit being developed.
Analyst Recommendation
Apply the necessary patches without delay. Maintaining the health of network security infrastructure is a critical component of a robust defense-in-depth strategy, and this update is essential for risk mitigation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
A security flaw in the Suricata IDS/IPS engine could permit attackers to interfere with network traffic analysis and security enforcement.
Executive Summary:
A vulnerability in the Suricata network engine poses a high risk to network visibility and the effectiveness of intrusion prevention measures.
Vulnerability Details
CVE-ID: CVE-2026-31932
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability involves a defect in the Suricata engine's packet handling or protocol analysis modules. An unauthenticated remote attacker could leverage this flaw to disrupt the monitoring capabilities of the IDS or cause the service to fail.
Business Impact
The failure of an IDS/IPS engine can lead to a "blind spot" in the corporate network, allowing malicious actors to operate without detection. With a CVSS score of 7.5, the potential for system downtime and the resulting loss of security oversight represents a significant risk to organizational assets and data security.
Remediation Plan
Immediate Action: Deploy the official security updates for Suricata immediately to address this engine-level vulnerability.
Proactive Monitoring: Review Suricata alert logs for anomalies and ensure that the engine is not dropping packets or entering an error state.
Compensating Controls: Use network segmentation to limit the blast radius of any potential intrusion that might bypass the affected IDS sensors.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. The critical nature of IDS software makes this a high-value target for attackers seeking to evade detection.
Analyst Recommendation
It is imperative to apply the recommended updates immediately. Security teams must treat any vulnerability in their monitoring infrastructure with the highest urgency to ensure that defensive capabilities remain intact.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
A high-severity vulnerability has been identified in the Suricata network IDS/IPS engine that may impact traffic inspection.
Executive Summary:
The Suricata network security engine is affected by a vulnerability that could allow attackers to bypass security monitoring or cause a denial of service.
Vulnerability Details
CVE-ID: CVE-2026-31931
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability affects the core processing engine of Suricata, a network intrusion detection and prevention system. An unauthenticated attacker could potentially send specially crafted network traffic to exploit this flaw, leading to engine instability or detection evasion.
Business Impact
As a critical component of network defense, a vulnerability in Suricata directly impacts the organization's ability to detect and block threats. The CVSS score of 7.5 reflects a high risk where the security appliance itself becomes a point of failure, potentially leading to undetected lateral movement by attackers or network downtime.
Remediation Plan
Immediate Action: Apply the latest security patches provided by the Suricata development team or your specific distribution maintainer.
Proactive Monitoring: Monitor the health and performance of Suricata sensors for unexpected crashes or high CPU utilization that may indicate exploitation.
Compensating Controls: Implement redundant security layers, such as host-based firewalls and endpoint detection, to mitigate the impact if the network IDS is bypassed.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. Given Suricata's role in security, any flaw in its engine is a high-priority concern for network administrators.
Analyst Recommendation
Immediate patching of all Suricata instances is required to maintain the security posture of the network. Administrators should verify that the engine is correctly processing traffic after the update to ensure continued protection against network-based threats.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
Suricata versions prior to 7.0.14 and 8.0.3 are vulnerable to a heap use-after-free condition caused by an unsigned integer overflow when generating excessive alerts for a single packet.
Executive Summary:
A heap use-after-free vulnerability in the Suricata network engine allows an unauthenticated remote attacker to potentially cause a denial of service or impact system integrity.
Vulnerability Details
CVE-ID: CVE-2026-22264
Affected Software: OISF Suricata
Affected Versions: < 7.0.14, >= 8.0.0, < 8.0.3
Vulnerability: The flaw is a heap use-after-free (CWE-416) triggered by an unsigned integer overflow during the alert generation process for high-traffic packets. This vulnerability is exploitable by an unauthenticated remote attacker capable of sending traffic that triggers excessive rule matches.
Business Impact
The exploitation of this vulnerability could lead to significant service disruption, as Suricata is a critical component for network intrusion detection and prevention. Given the CVSS score of 7.4, the risk is classified as High, reflecting the potential for system instability or integrity compromise within security infrastructure that relies on this engine for traffic inspection.
Remediation Plan
Immediate Action: Upgrade to Suricata version 7.0.14 or 8.0.3 immediately to apply the vendor-provided patch.
Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts of the Suricata process, which may indicate exploitation attempts.
Compensating Controls: If patching is not immediately feasible, reduce the complexity of active rulesets or ensure the system does not process untrusted rulesets to minimize the likelihood of triggering the overflow.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of January 29, 2026, there is no public information indicating active exploitation or a published proof-of-concept for this vulnerability. While the flaw is theoretically exploitable via specifically crafted network traffic, no weaponized exploit code has been identified in public repositories.
Analyst Recommendation
This vulnerability presents a notable risk to network security infrastructure and should be addressed with high priority. Organizations utilizing Suricata for critical traffic filtering must schedule the update to 7.0.14 or 8.0.3 during the next available maintenance window to ensure continued system stability and protection against potential exploitation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
Suricata versions 8.0.0 through 8.0.2 are vulnerable to a stack overflow due to uncontrolled recursion, potentially leading to a denial of service via a crash of the network monitoring engine.
Executive Summary:
A stack overflow vulnerability in Suricata versions 8.0.0 through 8.0.2 allows unauthenticated attackers to trigger a service crash, resulting in a denial of service.
Vulnerability Details
CVE-ID: CVE-2026-22260
Affected Software: OISF Suricata
Affected Versions: >= 8.0.0, < 8.0.3
Vulnerability: The software is susceptible to a stack overflow caused by uncontrolled recursion (CWE-674). An unauthenticated remote attacker can trigger this condition by sending crafted traffic that forces the engine to exceed its stack limits.
Business Impact
Successful exploitation of this vulnerability results in a denial of service, causing the Suricata engine to crash. Given that Suricata is a critical component for network intrusion detection and prevention, a crash leaves the network segment unmonitored and vulnerable to further exploitation by other threats. With a CVSS score of 7.5, the high availability impact justifies immediate attention to maintain security visibility.
Remediation Plan
Immediate Action: Update all instances of Suricata to version 8.0.3 or later to resolve the underlying recursion issue.
Proactive Monitoring: Monitor system logs for unexpected service termination or crash reports related to the Suricata process.
Compensating Controls: If immediate patching is not feasible, restore stability by reverting the configuration of request-body-limit and response-body-limit to their default values to mitigate the trigger conditions.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of January 29, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable via network-based traffic, making it a high priority for organizations relying on Suricata for perimeter or internal network defense.
Analyst Recommendation
This vulnerability represents a significant risk to network security infrastructure due to the potential for an unauthenticated attacker to disable monitoring capabilities. Organizations should prioritize updating to version 8.0.3 immediately to ensure continuous security operations and prevent service disruption.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
Specially crafted DNP3 traffic can trigger uncontrolled resource consumption in Suricata, leading to process memory exhaustion and potential service termination.
Executive Summary:
A vulnerability in the Suricata network engine allows unauthenticated remote attackers to cause a denial of service via memory exhaustion.
Vulnerability Details
CVE-ID: CVE-2026-22259
Affected Software: OISF Suricata
Affected Versions: < 7.0.14, >= 8.0.0, < 8.0.3
Vulnerability: This vulnerability involves uncontrolled resource consumption (CWE-400) within the DNP3 traffic parser. Unauthenticated attackers can send specifically crafted packets to trigger excessive memory allocation, causing the process to be terminated by the operating system OOM killer.
Business Impact
The exploitation of this vulnerability results in a denial of service for the network intrusion detection and prevention system. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to network visibility and security enforcement, potentially leaving the monitored infrastructure exposed to further attacks while the security engine is offline.
Remediation Plan
Immediate Action: Upgrade to Suricata version 7.0.14 or 8.0.3 immediately to implement the necessary memory management patches.
Proactive Monitoring: Monitor system logs and process status for unexpected service restarts or high memory utilization warnings associated with the Suricata process.
Compensating Controls: If patching is not immediately feasible, disable the DNP3 protocol parser in the Suricata YAML configuration file, as this feature is often disabled by default and serves as the primary attack vector.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of January 29, 2026, there is no public information indicating active exploitation or a published proof-of-concept for this vulnerability. The vulnerability is inherently exploitable by any network actor capable of sending traffic that reaches the Suricata inspection engine.
Analyst Recommendation
Organizations relying on Suricata for network security must prioritize this update to maintain operational stability and security posture. Given the ease of exploitation and the critical role of network monitoring, applying the vendor-supplied patch is the only definitive way to resolve the underlying resource consumption flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
Description Summary:
Suricata is vulnerable to uncontrolled resource consumption via crafted DCERPC traffic, which can lead to memory exhaustion and service termination.
Executive Summary:
Unauthenticated attackers can cause a denial of service in Suricata by sending crafted DCERPC traffic that triggers uncontrolled memory allocation.
Vulnerability Details
CVE-ID: CVE-2026-22258
Affected Software: OISF Suricata
Affected Versions: < 7.0.14, >= 8.0.0, < 8.0.3
Vulnerability: This vulnerability is an uncontrolled resource consumption flaw (CWE-400) where the application fails to limit buffer expansion when processing DCERPC traffic. The issue is reachable by unauthenticated remote attackers via UDP, TCP, or SMB protocols.
Business Impact
Successful exploitation results in process termination, causing a complete loss of network intrusion detection and prevention capabilities. Given the CVSS score of 7.5, this high severity vulnerability poses a critical threat to network security infrastructure, as a disruption of Suricata leaves the perimeter vulnerable to secondary attacks that would otherwise be blocked.
Remediation Plan
Immediate Action: Update Suricata to version 7.0.14 or 8.0.3 immediately to incorporate the necessary buffer management patches.
Proactive Monitoring: Monitor system logs for frequent process restarts or memory exhaustion errors that may indicate an attempt to trigger this crash.
Compensating Controls: For DCERPC over UDP, disable the parser. For DCERPC over TCP or SMB, configure the stream.reassembly.depth setting to impose a strict limit on buffered data.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of January 29, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its ability to be triggered remotely without authentication, which makes it highly automatable.
Analyst Recommendation
Organizations relying on Suricata for network security must prioritize this update, as the ability for an unauthenticated attacker to remotely crash an IPS/IDS engine presents an unacceptable security risk. Please apply the vendor provided patches or implement the recommended stream reassembly depth limits immediately to maintain operational integrity.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A stack-based buffer overflow in Suricata allows for potential denial of service when processing large buffers via Lua scripts.
Executive Summary:
A stack-based buffer overflow in the Suricata network engine, affecting versions prior to 7.0.13 and 8.0.2, poses a significant risk of service disruption.
Vulnerability Details
CVE-ID: CVE-2025-64344
Affected Software: OISF Suricata
Affected Versions: < 7.0.13, < 8.0.2
Vulnerability: The vulnerability is a stack-based buffer overflow (CWE-121) triggered when handling large data buffers within Lua scripts. This flaw is remotely exploitable by an unauthenticated attacker who can craft traffic to trigger the overflow during rule or output script processing.
Business Impact
The exploitation of this vulnerability leads to a denial of service, as the stack overflow causes the Suricata engine to crash. Given that Suricata is a critical component for network intrusion detection and prevention, an outage of this service leaves the network environment blind to malicious activity, effectively bypassing security controls. With a CVSS score of 7.5, this represents a high-severity risk to operational availability and network security posture.
Remediation Plan
Immediate Action: Update Suricata installations to version 7.0.13 or 8.0.2 immediately to incorporate the provided security patches.
Proactive Monitoring: Monitor service logs for unexpected process crashes or restarts associated with the Suricata engine, and audit Lua script execution patterns for signs of anomalous buffer usage.
Compensating Controls: If patching is not immediately feasible, disable all Lua-based rules and output scripts, or configure stream depth and HTTP response body limits to be less than half the available stack size.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the vulnerability is reachable without authentication, its primary impact is currently limited to service disruption rather than remote code execution.
Analyst Recommendation
The severity of this vulnerability stems from its ability to disable critical network security infrastructure without requiring authentication. Organizations relying on Suricata for perimeter or internal defense should prioritize the transition to version 7.0.13 or 8.0.2 during the next maintenance window. If immediate updates are not possible, the documented workarounds regarding Lua script management are essential to maintain system stability and prevent service degradation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A NULL pointer dereference vulnerability in Suricata versions 8.0.0 through 8.0.1 allows unauthenticated attackers to cause a denial of service via specifically crafted network traffic.
Executive Summary:
A NULL pointer dereference vulnerability in Suricata versions 8.0.0 to 8.0.1 poses a significant risk of service disruption to network security monitoring infrastructure.
Vulnerability Details
CVE-ID: CVE-2025-64335
Affected Software: OISF Suricata
Affected Versions: 8.0.0, 8.0.1
Vulnerability: This vulnerability is a NULL pointer dereference (CWE-476) occurring when the entropy keyword is utilized alongside base64_data in inspection rules. The flaw is remotely triggerable by an unauthenticated attacker, leading to an application crash.
Business Impact
The exploitation of this vulnerability results in a denial of service for the Suricata engine, effectively blinding security teams to network traffic during the outage. Given the CVSS score of 7.5, this high severity flaw could lead to significant gaps in intrusion detection and incident response capabilities, potentially allowing other malicious activities to go undetected while the service is offline.
Remediation Plan
Immediate Action: Upgrade to Suricata version 8.0.2 or later to apply the official patch provided by the OISF.
Proactive Monitoring: Monitor system logs for frequent service restarts or unexpected process terminations, which may indicate exploitation attempts.
Compensating Controls: If an immediate upgrade is not feasible, disable any inspection rules that utilize the entropy keyword in conjunction with base64_data to prevent triggering the vulnerable code path.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently susceptible to disruption as it can be triggered by standard network traffic patterns, making patching a priority for organizations relying on Suricata for critical network visibility.
Analyst Recommendation
Organizations should prioritize the update of all Suricata instances to version 8.0.2. The ease with which this vulnerability can be triggered via network traffic necessitates prompt action to maintain the integrity of security monitoring operations and prevent unintended service outages.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
Suricata versions 8.0.0 through 8.0.1 are vulnerable to unbounded memory growth during the decompression of compressed HTTP data, which can lead to a denial of service.
Executive Summary:
A vulnerability in Suricata versions 8.0.0 to 8.0.1 allows unauthenticated attackers to cause a denial of service through uncontrolled memory consumption.
Vulnerability Details
CVE-ID: CVE-2025-64334
Affected Software: OISF Suricata
Affected Versions: 8.0.0 to 8.0.1
Vulnerability: This flaw is an allocation of resources without limits (CWE-770), specifically triggered during the decompression of HTTP response bodies. An unauthenticated attacker can send crafted compressed traffic to exhaust system memory, leading to service failure.
Business Impact
Successful exploitation of this vulnerability results in a denial of service, effectively disabling network monitoring and intrusion detection capabilities. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to network visibility and security posture, potentially leaving systems blind to other malicious activities during the outage.
Remediation Plan
Immediate Action: Upgrade to Suricata version 8.0.2 or later to apply the necessary memory allocation limits.
Proactive Monitoring: Monitor system memory usage on Suricata sensors and review logs for repeated service crashes or unexpected resource exhaustion patterns.
Compensating Controls: If immediate patching is not feasible, disable LZMA decompression or reduce the response-body-limit configuration to mitigate the potential for unbounded memory growth.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any network-adjacent actor capable of sending traffic that the sensor attempts to inspect.
Analyst Recommendation
The risk of service disruption via memory exhaustion is significant for critical network security infrastructure. Organizations should prioritize upgrading to version 8.0.2 immediately to ensure the stability and reliability of their Suricata deployment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A stack-based buffer overflow in Suricata allows unauthenticated remote attackers to crash the service by sending a large HTTP content type during logging.
Executive Summary:
A stack-based buffer overflow in the Suricata network engine, affecting versions prior to 7.0.13 and 8.0.2, poses a significant denial of service risk.
Vulnerability Details
CVE-ID: CVE-2025-64333
Affected Software: OISF Suricata
Affected Versions: < 7.0.13, < 8.0.2
Vulnerability: The vulnerability is a stack-based buffer overflow (CWE-121) triggered when the engine processes an excessively large HTTP content type during logging. This flaw allows an unauthenticated remote attacker to cause a service crash, effectively disabling the network monitoring capabilities of the affected infrastructure.
Business Impact
The successful exploitation of this vulnerability results in a denial of service, which directly impacts the operational integrity of network security monitoring. With a CVSS score of 7.5, the risk is classified as High, as it allows unauthenticated attackers to disrupt critical security visibility, potentially masking further malicious activity while the IDS/IPS engine is offline.
Remediation Plan
Immediate Action: Upgrade all instances of Suricata to version 7.0.13, 8.0.2, or later to eliminate the vulnerability.
Proactive Monitoring: Monitor system logs for unexpected service restarts or process crashes that may indicate an attempt to trigger the buffer overflow.
Compensating Controls: If immediate patching is not feasible, restrict the stream reassembly depth via the configuration setting stream.reassembly.depth to less than half the stack size, or increase the process stack size to reduce the likelihood of a crash.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its potential for remote, unauthenticated exploitation against a critical security component.
Analyst Recommendation
Given the critical role of Suricata in perimeter and network defense, the inability to monitor traffic due to a forced crash represents a significant security gap. Administrators should prioritize the deployment of the provided patches in version 7.0.13 or 8.0.2 immediately to restore stable and secure operations.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A stack-based buffer overflow in Suricata allows unauthenticated attackers to cause a denial of service via specifically crafted SWF decompression tasks.
Executive Summary:
A stack-based buffer overflow vulnerability in the Suricata network engine allows unauthenticated attackers to crash the service, resulting in a potential denial of service.
Vulnerability Details
CVE-ID: CVE-2025-64332
Affected Software: OISF Suricata
Affected Versions: < 7.0.13, < 8.0.2
Vulnerability: This vulnerability is a stack-based buffer overflow (CWE-121) triggered during SWF decompression. It can be exploited by an unauthenticated network-based attacker to cause the Suricata engine to crash.
Business Impact
The vulnerability carries a CVSS score of 7.5, which falls into the High severity range. As Suricata is a critical component for network intrusion detection and prevention, a successful exploit would result in a denial of service, effectively blinding security teams to malicious network activity and leaving the organization vulnerable to further undetected attacks.
Remediation Plan
Immediate Action: Update to Suricata version 7.0.13 or 8.0.2 immediately to incorporate the provided security patches.
Proactive Monitoring: Monitor network logs for service interruptions or unexpected process terminations associated with the Suricata daemon.
Compensating Controls: If patching is not immediately feasible, disable SWF decompression by setting swf-decompression to false in the suricata.yaml configuration file, as this feature is disabled by default.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the flaw is theoretically exploitable over the network, the requirement for SWF decompression to be enabled limits the attack surface for default deployments.
Analyst Recommendation
The vulnerability poses a significant risk to organizational visibility by targeting the very security infrastructure intended to monitor the network. Administrators should prioritize patching to the latest stable versions to eliminate the stack overflow condition, or ensure the non-essential SWF decompression feature remains disabled in their environment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A stack-based buffer overflow exists in Suricata prior to versions 7.0.13 and 8.0.2, triggered during large HTTP file transfers when specific logging and response limit configurations are enabled.
Executive Summary:
A stack-based buffer overflow in the Suricata network engine allows unauthenticated remote attackers to cause a denial of service condition.
Vulnerability Details
CVE-ID: CVE-2025-64331
Affected Software: OISF Suricata
Affected Versions: < 7.0.13, < 8.0.2
Vulnerability: This vulnerability is a stack-based buffer overflow (CWE-121) that occurs when processing large HTTP file transfers if the HTTP response body limit is increased and printable HTTP body logging is enabled. The vulnerability is remotely exploitable by an unauthenticated attacker.
Business Impact
The exploitation of this vulnerability results in a denial of service, potentially crashing the Suricata inspection engine. Given that Suricata is often deployed as a critical security control (IDS/IPS), a successful crash could leave the network environment unprotected, significantly increasing the risk of unmonitored malicious activity. With a CVSS score of 7.5, this is classified as a High severity issue requiring prompt attention to maintain network visibility and security posture.
Remediation Plan
Immediate Action: Update Suricata installations to version 7.0.13 or 8.0.2 immediately to incorporate the vendor-supplied security patches.
Proactive Monitoring: Review system logs for unexpected process crashes or service restarts that may indicate attempted exploitation of the buffer overflow.
Compensating Controls: If patching cannot be performed immediately, mitigate the risk by reverting HTTP response body limits to default values and disabling http-body-printable logging, which is not enabled by default.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by sending specially crafted large HTTP traffic if the vulnerable configuration is active.
Analyst Recommendation
This vulnerability presents a significant risk to network monitoring infrastructure, particularly for organizations that have customized their Suricata configurations for deep packet inspection. Administrators should prioritize the application of the official patches provided by OISF. If immediate patching is not feasible, the recommended configuration changes should be implemented to reduce the attack surface until the software can be updated.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A heap-based buffer overflow in Suricata versions prior to 7.0.13 and 8.0.2 can lead to service crashes when processing specific alert and drop records.
Executive Summary:
A heap-based buffer overflow vulnerability in the Suricata network engine allows unauthenticated attackers to trigger a denial of service via service crashes.
Vulnerability Details
CVE-ID: CVE-2025-64330
Affected Software: OISF Suricata
Affected Versions: < 7.0.13, < 8.0.2
Vulnerability: This vulnerability is a heap-based buffer overflow (CWE-122) occurring during the logging of verdict records in eve.alert and eve.drop. An unauthenticated attacker can trigger this condition by filling the per-packet alert queue and subsequently triggering a pass rule.
Business Impact
The vulnerability poses a direct threat to network availability, as a successful exploit causes the Suricata engine to crash. Given that Suricata often acts as a primary network defense component, its failure results in a significant blind spot for security operations, potentially allowing other malicious traffic to pass through undetected. With a CVSS score of 7.5, this high-severity flaw requires immediate attention to maintain the integrity of security monitoring infrastructure.
Remediation Plan
Immediate Action: Upgrade to Suricata version 7.0.13 or 8.0.2 to implement the upstream fix.
Proactive Monitoring: Monitor system logs for frequent engine crashes or unexpected service restarts, and consider increasing the packet-alert-max value in the suricata.yaml configuration file as a temporary mitigation to reduce the likelihood of the overflow.
Compensating Controls: Ensure that network traffic is segmented and monitored, and employ secondary defensive layers to ensure visibility remains intact should the primary IDS/IPS service fail.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of November 28, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by network-adjacent attackers who can influence the alert queue state, but it requires specific traffic conditions to trigger.
Analyst Recommendation
This vulnerability represents a significant risk to the stability of your network security stack. Organizations should prioritize updating to the patched versions of Suricata as soon as possible to prevent potential service disruption. If an immediate update is not feasible, increasing the alert queue size provides a necessary tactical buffer while scheduling the required maintenance.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
Suricata version 8.0.0 is susceptible to a NULL pointer dereference when processing the tls.subjectaltname keyword if the decoded subjectaltname contains a NULL byte, leading to a segmentation fault.
Executive Summary:
A NULL pointer dereference vulnerability in Suricata version 8.0.0 can be exploited by an unauthenticated attacker to cause a denial of service via a segmentation fault.
Vulnerability Details
CVE-ID: CVE-2025-59150
Affected Software: OISF Suricata
Affected Versions: >= 8.0.0, < 8.0.1
Vulnerability: This vulnerability is a NULL pointer dereference (CWE-476) occurring within the tls.subjectaltname keyword processing logic. An unauthenticated attacker can trigger this condition by providing a specially crafted subjectaltname containing a NULL byte.
Business Impact
The exploitation of this vulnerability results in a segmentation fault, which causes the Suricata process to crash. Given that Suricata serves as a critical network IDS/IPS engine, this denial of service condition leaves the network environment blind to potential threats, effectively disabling security monitoring infrastructure. The CVSS score of 7.5 reflects a High severity due to the ease of triggering the crash remotely without authentication.
Remediation Plan
Immediate Action: Update Suricata to version 8.0.1 or later to resolve the underlying code defect.
Proactive Monitoring: Review system logs for frequent Suricata service restarts or unexpected process terminations that may indicate exploitation attempts.
Compensating Controls: If an immediate update is not feasible, disable any inspection rules that utilize the tls.subjectaltname keyword to prevent the triggering of the vulnerable code path.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of October 2, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any network traffic that traverses the sensor and triggers the specific keyword condition, making it a viable target for remote denial of service.
Analyst Recommendation
This vulnerability presents a significant risk to network availability and security visibility. Administrators should prioritize patching to version 8.0.1 immediately, as the vulnerability is remotely exploitable and does not require authentication. If patching is delayed, the provided workaround of disabling specific rules is essential to maintain the stability of the security appliance.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
Suricata versions 8.0.0 and below contain a NULL pointer dereference vulnerability in the entropy keyword handling, which can lead to a segmentation fault and service disruption.
Executive Summary:
A vulnerability in the Suricata network engine allows unauthenticated attackers to trigger a denial of service via a segmentation fault.
Vulnerability Details
CVE-ID: CVE-2025-59148
Affected Software: OISF Suricata
Affected Versions: < 8.0.1
Vulnerability: This is a NULL pointer dereference (CWE-476) occurring when the entropy keyword is not anchored to a sticky buffer. An unauthenticated remote attacker can trigger this condition by sending traffic that matches a malformed rule, resulting in the termination of the Suricata process.
Business Impact
The exploitation of this flaw leads to a denial of service for the network intrusion detection and prevention systems. Given a CVSS score of 7.5, the impact is significant because the loss of visibility or active filtering capabilities leaves the network exposed to other malicious activities. Organizations relying on Suricata for perimeter security or compliance monitoring face operational risk during the period of service unavailability.
Remediation Plan
Immediate Action: Update the Suricata software to version 8.0.1 or later to incorporate the official patch.
Proactive Monitoring: Monitor service logs for unexpected process crashes, segmentation faults, or recurring restarts of the Suricata engine.
Compensating Controls: If immediate patching is not feasible, disable any rules that utilize the entropy keyword or ensure that all such rules are correctly anchored to a sticky buffer as specified by the vendor.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of October 2, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any network traffic that triggers the vulnerable rule logic, making it a high priority for environments with untrusted ingress traffic.
Analyst Recommendation
This vulnerability presents a clear risk of service disruption for essential security infrastructure. Administrators should prioritize the deployment of version 8.0.1 across all affected Suricata instances to ensure continued stability and security coverage. If an immediate update is not possible, implementing the vendor-provided configuration workaround is necessary to prevent potential denial of service attacks.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
Suricata versions 7.0.11 and below, and version 8.0.0, are vulnerable to a detection bypass via crafted TCP SYN packets, leading to potential security monitoring failures.
Executive Summary:
A vulnerability in the Suricata network engine allows unauthenticated attackers to bypass detection and logging mechanisms by sending crafted TCP traffic.
Vulnerability Details
CVE-ID: CVE-2025-59147
Affected Software: OISF Suricata
Affected Versions: OISF suricata: < 7.0.12, >= 8.0.0, < 8.0.1
Vulnerability: This flaw stems from improper security checks regarding TCP flow handling, where multiple SYN packets with differing sequence numbers within a single flow tuple cause the engine to ignore the session. The attack is unauthenticated and can be triggered remotely by sending specifically crafted network traffic.
Business Impact
The inability of an IDS or IPS to properly monitor network traffic represents a significant security oversight. In IDS mode, this vulnerability allows malicious activity to remain undetected by security teams, while in IPS mode, it may result in the unintentional blocking of legitimate traffic. With a CVSS score of 7.5, this high severity issue directly undermines the efficacy of perimeter and internal network defenses.
Remediation Plan
Immediate Action: Upgrade to Suricata versions 7.0.12 or 8.0.1 immediately to implement the required flow handling logic fixes.
Proactive Monitoring: Review network traffic logs for patterns involving unusual TCP handshake sequences or high volumes of SYN packets that may indicate an attempt to probe or bypass security sensors.
Compensating Controls: Ensure that network traffic is inspected by secondary, heterogeneous security layers to maintain visibility if the primary Suricata sensor is rendered ineffective.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of October 2, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its ability to blind security infrastructure to malicious payloads, though it requires specific knowledge of the target's traffic handling logic to execute effectively.
Analyst Recommendation
Organizations relying on Suricata for critical network visibility must treat this vulnerability as a priority. Failure to patch allows attackers to bypass existing security controls silently, rendering defensive monitoring tools unreliable. Apply the vendor-provided updates immediately to restore full inspection capabilities and prevent potential detection evasion.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
Description Summary:
A vulnerability in Suricata allows unauthenticated attackers to cause uncontrolled memory usage via crafted HTTP/2 stream 0 data, resulting in a potential loss of network security monitoring visibility.
Executive Summary:
Suricata is susceptible to an uncontrolled resource consumption vulnerability that can lead to a denial of service by exhausting system memory during HTTP/2 traffic processing.
Vulnerability Details
CVE-ID: CVE-2025-53538
Affected Software: OISF Suricata
Affected Versions: < 7.0.11, >= 8.0.0-beta1, < 8.0.0
Vulnerability: This flaw involves the improper handling of data on HTTP/2 stream 0, which triggers uncontrolled memory allocation (CWE-770/CWE-400). The attack vector is network-based and requires no authentication or user interaction to exploit.
Business Impact
Successful exploitation of this vulnerability results in a denial of service for the network security monitoring infrastructure. Because Suricata functions as an IDS/IPS, a crash or memory exhaustion event directly compromises the security posture of the organization by creating a blind spot in traffic inspection, potentially allowing malicious activity to pass undetected. The CVSS score of 7.5 reflects the high availability impact this flaw poses to critical security infrastructure.
Remediation Plan
Immediate Action: Update Suricata to version 7.0.11 or 8.0.0 as soon as possible to incorporate the necessary resource management patches.
Proactive Monitoring: Monitor system memory usage and Suricata process stability for unexpected spikes or service restarts that may indicate attempted exploitation.
Compensating Controls: If immediate patching is not feasible, disable the HTTP/2 parser or implement the recommended Suricata signature to drop malicious HTTP/2 frame types targeting stream 0.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of 2025-07-23, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its ability to be triggered remotely over the network without authentication, which could lead to widespread service disruption if targeted.
Analyst Recommendation
Given that Suricata is a foundational component of network defense, this vulnerability presents a significant risk to overall visibility. Security teams should prioritize the deployment of the vendor-provided patches. If patching must be delayed, the provided detection and mitigation signatures should be applied immediately to neutralize the threat vector while maintaining operational continuity.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces
LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces
Description Summary:
A memory leak in the libhtp HTTP parser allows unauthenticated remote attackers to cause a denial of service by starving the process of memory, leading to a loss of network traffic visibility.
Executive Summary:
A memory leak vulnerability in the OISF libhtp library, version 0.5.50 and below, poses a significant denial of service risk by enabling resource exhaustion through specially crafted traffic.
Vulnerability Details
CVE-ID: CVE-2025-53537
Affected Software: OISF libhtp
Affected Versions: < 0.5.51
Vulnerability: This vulnerability is classified as a missing release of memory after effective lifetime (CWE-401). It can be triggered by an unauthenticated remote attacker through traffic-induced memory exhaustion, effectively causing the application process to crash or become unresponsive.
Business Impact
The primary impact of this vulnerability is the loss of system availability and network traffic visibility. Because libhtp is a core component for security-aware parsing, a successful exploit could blind security monitoring tools, such as Suricata, to malicious activity occurring on the network. With a CVSS score of 7.5, the risk is considered high due to the ease of remote exploitation and the potential for complete service disruption.
Remediation Plan
Immediate Action: Update libhtp to version 0.5.51 or higher to resolve the underlying memory leak.
Proactive Monitoring: Monitor system memory usage for unusual spikes and review application logs for errors related to memory allocation or service restarts.
Compensating Controls: If immediate patching is not feasible, implement the suggested workaround by setting the configuration parameter suricata.yaml app-layer.protocols.http.libhtp.default-config.lzma-enabled to false.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of July 24, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any network participant capable of sending traffic to the target parser, making it a high-priority stability concern for network security infrastructure.
Analyst Recommendation
Given that this vulnerability allows for unauthenticated denial of service and directly impacts security visibility, it should be addressed with high urgency. Organizations relying on libhtp for deep packet inspection or traffic analysis must prioritize the update to version 0.5.51 to ensure continued operational integrity and monitoring efficacy.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Description Summary:
A vulnerability identified in the Suricata network engine could be exploited to disrupt security monitoring or bypass detection mechanisms.
Executive Summary:
Suricata IDS/IPS sensors are affected by a high-severity vulnerability that poses a direct threat to network security and threat detection capabilities.
Vulnerability Details
CVE-ID: CVE-2026-31937
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability resides in the Suricata engine, impacting its network IDS and IPS functions. An unauthenticated attacker could potentially exploit this flaw through specially crafted network traffic, leading to a denial of service or detection evasion.
Business Impact
With a CVSS score of 7.5, this vulnerability represents a high risk to organizational security. A failure in the Suricata engine can leave the network vulnerable to various attacks, leading to potential data breaches, system compromise, and significant reputational damage if an intrusion goes undetected.
Remediation Plan
Immediate Action: Update all affected Suricata instances to the latest secure version immediately to mitigate the risk of exploitation.
Proactive Monitoring: Monitor for unexpected service restarts or unusual traffic patterns that might indicate an attempt to exploit the IDS engine.
Compensating Controls: Maintain up-to-date endpoint security and centralized logging to provide alternative methods of detection for malicious activity.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, the high severity underscores the need for prompt patching.
Analyst Recommendation
Immediate action is required to patch the Suricata engine. Security administrators should prioritize this update to ensure that the network's primary intrusion detection and prevention system remains effective and resilient.