Network Intrusion Detection System Vulnerability in Suricata by OISF
CVE-2026-45747
7.5HIGH
What is CVE-2026-45747?
Suricata, a prominent network intrusion detection and prevention system, is affected by a vulnerability that arises from the Lua TLS certificate information helper. This issue occurs when certain TLS certificate fields are absent, leading to the potential dereferencing of NULL fields during Lua script executions. As a result, crafted TLS traffic could trigger crashes in Suricata, causing a denial of service condition. Users are advised to avoid using the TlsGetCertInfo function on untrusted traffic or to implement safeguards in their Lua scripts to appropriately handle missing certificate fields. The vulnerability is addressed in version 7.0.16.
Affected Version(s)
suricata < 7.0.16
