Null Pointer Dereference in Suricata Network Security Monitoring Engine
CVE-2026-57225
3.3LOW
What is CVE-2026-57225?
A vulnerability in Suricata's network Intrusion Detection System and Network Security Monitoring engine may lead to a NULL pointer dereference during startup, configuration test mode, or rule reload processes. This occurs when a configured JSON or NDJSON dataset's value_key does not resolve to a string, potentially originating from either trusted or untrusted dataset sources. This can result in a crash before any traffic is processed, affecting system capabilities. The issue has been addressed in Suricata version 8.0.6.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6
