Network Detection Bypass in Suricata by Open Information Security Foundation
CVE-2025-59147
What is CVE-2025-59147?
A vulnerability in Suricata, a network IDS and IPS engine, allows attackers to bypass detection by sending crafted traffic with multiple SYN packets featuring different sequence numbers within the same flow tuple. This manipulation can cause Suricata to fail in identifying the TCP session correctly. In IDS mode, this results in a logging bypass, while in IPS mode, it prevents the appropriate flow from being blocked. Users are advised to update to versions 7.0.12 or 8.0.1 to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
suricata < 7.0.12 < 7.0.12
suricata >= 8.0.0, < 8.0.1 < 8.0.0, 8.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
