suricata
OISF- Software type
- —
- Catalog vulnerabilities
- 80
Severity across 66 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 66 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 80 vulnerability records affecting suricata.
Among the 66 records analyzed by CyStack, 47 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-45770Suricata lua: excessive flow variable registration can bypass sandbox | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45769ikev2: unbounded client transform storage can lead to resource exhaustion | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45768Suricata ldap: unbounded responses per transaction can lead to resource exhaustion | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45767Suricata datasets: save to absolute filename can be bypassed when combined with load command | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityMedium |
CVE-2026-45766Suricata nfs: unbounded stateful structures can lead to resource exhaustion | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45765Suricata dnp3: unbounded reassembly can lead to resource exhaustion | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45764Suricata http2: protocol-change type confusion can lead to denial of service | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityCritical |
CVE-2026-45762Suricata defrag: missing address-family check can lead to remote crash | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45761Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityLow |
CVE-2026-45759Suricata http1: quadratic Content-Disposition processing can lead to denial of service | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45752Suricata detect/transform: use-after-free in decompress transforms | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityMedium |
CVE-2026-45751Suricata detect/transform: use-after-free in dotprefix transform | Exploitation statusNot confirmed | FixNot confirmed | Published09/10/2026 | SeverityMedium |
CVE-2026-45747Suricata lua/tls: null dereference in TlsGetCertInfo | Exploitation statusPublic exploit | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-46387Suricata http2: decompression bomb can cause denial of service in Suricata | Exploitation statusNot known exploited | FixNot confirmed | Published09/10/2026 | SeverityHigh |
CVE-2026-45763Suricata lua: sandbox allocation limit not enforced for new allocations | Exploitation statusNot known exploited | FixNot confirmed | Published09/10/2026 | SeverityMedium |
CVE-2026-31937Suricata dcerpc: quadratic complexity in dcerpc buffering | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2026-31935Suricata http2: unbounded resource consumption | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2026-31934Suricata smtp/mine: quadratic complexity in extracting urls | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2026-31933Suricata stream: quadratic complexity in stream inspection | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2026-31932Suricata krb5: quadratic complexity in krb5 buffering | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2026-31931Suricata tls: null dereference in tls.alpn rule keyword | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2026-22264Suricata detect/alert: heap-use-after-free on alert queue expansion | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityHigh |
CVE-2026-22263Suricata http1: quadratic complexity in headers parsing over multiple packets | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityMedium |
CVE-2026-22262Suricata datasets: stack overflow when saving a set | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityMedium |
CVE-2026-22261Suricata eve/alert: http1 xff handling can lead to denial of service | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityLow |
CVE-2026-22260Suricata http1: infinite recursion in decompression | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityHigh |
CVE-2026-22259Suricata dnp3: unbounded transaction growth | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityHigh |
CVE-2026-22258Suricata DCERPC: unbounded fragment buffering leads to memory exhaustion | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityHigh |
CVE-2025-64344Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-64330Suricata is vulnerable to a heap buffer overflow on verdict | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-64331Suricata is vulnerable to a stack overflow on large file transfers with http-body-printable | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-64332Suricata is vulnerable to a stack overflow on larger compressed data | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-64333Suricata is vulnerable to a stack overflow from big content-type | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-64335Suricata is vulnerable to a null deref when used with base64_data | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-64334Suricata is vulnerable to unbounded memory growth for decompression | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityHigh |
CVE-2025-59150Suricata: Keyword tls.subjectaltname can lead to NULL-ptr deref | Exploitation statusNot known exploited | FixYes | Published10/01/2025 | SeverityHigh |
CVE-2025-59149Suricata: Stack buffer overflow in rule parser when processing long keywords with transforms | Exploitation statusNot known exploited | FixYes | Published10/01/2025 | SeverityMedium |
CVE-2025-59148Suricata's improper use of entropy keyword can lead to a NULL-ptr deref | Exploitation statusNot known exploited | FixYes | Published10/01/2025 | SeverityHigh |
CVE-2025-59147Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN Packets | Exploitation statusNot known exploited | FixYes | Published10/01/2025 | SeverityHigh |
CVE-2025-53538Suricata's mishandling of data on HTTP2 stream 0 can lead to resource starvation | Exploitation statusNot known exploited | FixYes | Published07/22/2025 | SeverityHigh |
CVE-2025-29918Suricata pcre: negated pcr can cause infinite loop | Exploitation statusNot known exploited | FixYes | Published04/10/2025 | SeverityMedium |
CVE-2025-29917Suricata decode_base64: signature can do large memory allocation | Exploitation statusNot known exploited | FixYes | Published04/10/2025 | SeverityMedium |
CVE-2025-29916Suricata datasets: ruleset declared settings can lead to resource starvation | Exploitation statusNot known exploited | FixYes | Published04/10/2025 | SeverityMedium |
CVE-2025-29915Suricata af-packet: defrag option can lead to truncated packets affecting visibility | Exploitation statusNot known exploited | FixNot confirmed | Published04/10/2025 | SeverityHigh |
CVE-2024-55629Suricata generic detection bypass using TCP urgent support | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2025 | SeverityHigh |
CVE-2024-55628Suricata oversized resource names utilizing DNS name compression can lead to resource starvation | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2025 | SeverityHigh |
CVE-2024-55627Suricata segfault on StreamingBufferSlideToOffsetWithRegions | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2025 | SeverityMedium |
CVE-2024-55626Suricata oversized bpf file can lead to buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2025 | SeverityLow |
CVE-2024-55605Suricata allows stack overflow in transforms | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2025 | SeverityHigh |
CVE-2024-47522Suricata ja4: invalid alpn leads to panic | Exploitation statusPublic exploit | FixNot confirmed | Published10/16/2024 | SeverityHigh |
CVE-2024-47188Suricata http/byte-ranges: missing hashtable random seed leads to potential DoS | Exploitation statusNot known exploited | FixNot confirmed | Published10/16/2024 | SeverityHigh |
CVE-2024-47187Suricata datasets: missing hashtable random seed leads to potential DoS | Exploitation statusNot known exploited | FixNot confirmed | Published10/16/2024 | SeverityHigh |
CVE-2024-45796Suricata defrag: off by one can lead to policy bypass | Exploitation statusNot known exploited | FixNot confirmed | Published10/16/2024 | SeverityMedium |
CVE-2024-45795Suricata detect/datasets: reachable assertion with unimplemented rule option | Exploitation statusNot known exploited | FixNot confirmed | Published10/16/2024 | SeverityHigh |
CVE-2024-38536Suricata http/range: NULL-ptr deref when http.memcap is reached | Exploitation statusNot known exploited | FixNot confirmed | Published07/11/2024 | SeverityHigh |
CVE-2024-38535Suricata http2: oom from duplicate headers | Exploitation statusNot known exploited | FixNot confirmed | Published07/11/2024 | SeverityHigh |
CVE-2024-38534Suricata modbus: txs without responses are never freed | Exploitation statusNot known exploited | FixNot confirmed | Published07/11/2024 | SeverityHigh |
CVE-2024-37151Suricata defrag: IP ID reuse can lead to policy bypass | Exploitation statusNot known exploited | FixNot confirmed | Published07/11/2024 | SeverityMedium |
CVE-2024-32867Suricata's defrag contains various issues leading to policy bypass | Exploitation statusNot known exploited | FixYes | Published05/07/2024 | SeverityMedium |
CVE-2024-32664Suricata's base64 contains an out of bounds write | Exploitation statusNot known exploited | FixYes | Published05/07/2024 | SeverityMedium |
CVE-2024-32663Suricata 's http2 parser contains an improper compressed header handling can lead to resource starvation | Exploitation statusNot known exploited | FixNot confirmed | Published05/07/2024 | SeverityHigh |
CVE-2024-28870Suricata uses excessive resource use in malformed ssh traffic parsing | Exploitation statusNot known exploited | FixYes | Published04/03/2024 | SeverityHigh |
CVE-2024-24568Suricata http2: header handling evasion | Exploitation statusNot known exploited | FixYes | Published02/26/2024 | SeverityMedium |
CVE-2024-23839Suricata http: heap use after free with http.request_header and http.response_header keywords | Exploitation statusNot known exploited | FixYes | Published02/26/2024 | SeverityHigh |
CVE-2024-23836crafted traffic can cause denial of service | Exploitation statusNot known exploited | FixYes | Published02/26/2024 | SeverityHigh |
CVE-2024-23835Suricata's pgsql: memory exhaustion use on record parsing | Exploitation statusNot known exploited | FixYes | Published02/26/2024 | SeverityHigh |
CVE-2023-35852CVE-2023-35852 | Exploitation statusNot known exploited | FixNot confirmed | Published06/19/2023 | SeverityUnknown |
CVE-2023-35853CVE-2023-35853 | Exploitation statusNot known exploited | FixNot confirmed | Published06/19/2023 | SeverityUnknown |
CVE-2020-19678CVE-2020-19678 | Exploitation statusPublic exploit | FixNot confirmed | Published04/06/2023 | SeverityHigh |
CVE-2021-45098CVE-2021-45098 | Exploitation statusNot confirmed | FixNot confirmed | Published12/16/2021 | SeverityUnknown |
CVE-2021-37592CVE-2021-37592 | Exploitation statusNot confirmed | FixNot confirmed | Published11/19/2021 | SeverityUnknown |
CVE-2021-35063CVE-2021-35063 | Exploitation statusNot confirmed | FixNot confirmed | Published07/22/2021 | SeverityUnknown |
CVE-2019-18625CVE-2019-18625 | Exploitation statusNot confirmed | FixNot confirmed | Published01/06/2020 | SeverityUnknown |
CVE-2019-18792CVE-2019-18792 | Exploitation statusNot confirmed | FixNot confirmed | Published01/06/2020 | SeverityUnknown |
CVE-2019-1010279CVE-2019-1010279 | Exploitation statusNot confirmed | FixNot confirmed | Published07/18/2019 | SeverityUnknown |
CVE-2019-1010251CVE-2019-1010251 | Exploitation statusNot confirmed | FixNot confirmed | Published07/18/2019 | SeverityUnknown |
CVE-2019-10050CVE-2019-10050 | Exploitation statusNot confirmed | FixNot confirmed | Published05/13/2019 | SeverityUnknown |
CVE-2018-10244CVE-2018-10244 | Exploitation statusNot confirmed | FixNot confirmed | Published04/04/2019 | SeverityUnknown |
CVE-2018-10242CVE-2018-10242 | Exploitation statusNot confirmed | FixNot confirmed | Published04/04/2019 | SeverityUnknown |
CVE-2013-5919CVE-2013-5919 | Exploitation statusNot confirmed | FixNot confirmed | Published05/30/2014 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan