Network Detection Bypass in Suricata by Open Information Security Foundation
CVE-2025-59147

7.5HIGH

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
1 October 2025

What is CVE-2025-59147?

A vulnerability in Suricata, a network IDS and IPS engine, allows attackers to bypass detection by sending crafted traffic with multiple SYN packets featuring different sequence numbers within the same flow tuple. This manipulation can cause Suricata to fail in identifying the TCP session correctly. In IDS mode, this results in a logging bypass, while in IPS mode, it prevents the appropriate flow from being blocked. Users are advised to update to versions 7.0.12 or 8.0.1 to mitigate this issue.

Affected Version(s)

suricata < 7.0.12 < 7.0.12

suricata >= 8.0.0, < 8.0.1 < 8.0.0, 8.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59147 : Network Detection Bypass in Suricata by Open Information Security Foundation