Denial of Service Risk in Suricata Network Security Monitoring Engine
CVE-2026-57224

6.5MEDIUM

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-57224?

Suricata, a widely used network Intrusion Detection and Prevention System, is affected by a vulnerability in its DHCP and RDP parsers, where transactions are created without proper state management regarding packet direction. This oversight can lead to an unbounded growth of per-flow transaction lists, causing increasing CPU and memory utilization, potentially resulting in a denial of service. Users are advised to upgrade to version 8.0.6 or later to mitigate these issues.

Affected Version(s)

suricata >= 8.0.0, < 8.0.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.