CVE-2026-22264
- EPSS 0.06%
- Veröffentlicht 27.01.2026 18:33:50
- Zuletzt bearbeitet 29.01.2026 20:58:58
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 cont...
CVE-2026-22263
- EPSS 0.02%
- Veröffentlicht 27.01.2026 18:27:45
- Zuletzt bearbeitet 29.01.2026 21:00:55
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available...
CVE-2026-22262
- EPSS 0.08%
- Veröffentlicht 27.01.2026 18:18:52
- Zuletzt bearbeitet 29.01.2026 21:01:55
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0...
CVE-2026-22261
- EPSS 0.05%
- Veröffentlicht 27.01.2026 18:10:27
- Zuletzt bearbeitet 29.01.2026 21:02:34
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a work...
CVE-2026-22260
- EPSS 0.02%
- Veröffentlicht 27.01.2026 17:30:39
- Zuletzt bearbeitet 29.01.2026 21:03:54
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values for `request-body-limit` and `response...
CVE-2026-22259
- EPSS 0.06%
- Veröffentlicht 27.01.2026 17:16:12
- Zuletzt bearbeitet 30.01.2026 20:01:49
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out o...
CVE-2026-22258
- EPSS 0.05%
- Veröffentlicht 27.01.2026 16:17:29
- Zuletzt bearbeitet 30.01.2026 20:09:24
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UD...
CVE-2025-64344
- EPSS 0.07%
- Veröffentlicht 26.11.2025 23:05:33
- Zuletzt bearbeitet 03.12.2025 16:06:06
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users o...
CVE-2025-64330
- EPSS 0.08%
- Veröffentlicht 26.11.2025 23:03:40
- Zuletzt bearbeitet 05.12.2025 13:30:59
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve....
CVE-2025-64331
- EPSS 0.07%
- Veröffentlicht 26.11.2025 23:00:40
- Zuletzt bearbeitet 08.12.2025 19:30:34
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow can occur on large HTTP file transfers if the user has increas...