Heap Buffer Overflow in Suricata Network Security Solutions
CVE-2026-45761

3.3LOW

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-45761?

A severe vulnerability exists in Suricata, a leading network Intrusion Detection and Prevention System. When utilizing mixed-case frame syntax, a specially crafted rule can lead to a heap buffer overflow during the signature loading process. This issue occurs during the parsing and loading of rules, not solely from incoming network traffic. Users are urged to upgrade to versions 7.0.16 and 8.0.5 or later to ensure their systems are protected. As a precaution, it is recommended to preprocess rules to verify that frame syntax is in lowercase and to only use trusted rulesets.

Affected Version(s)

suricata >= 8.0.0, < 8.0.5 < 8.0.0, 8.0.5

suricata < 7.0.16 < 7.0.16

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.