Heap Buffer Overflow in Suricata Network Security Monitoring Engine
CVE-2026-57226

3.7LOW

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-57226?

Suricata, a well-known network intrusion detection and prevention system, is vulnerable to a heap buffer overflow due to improper handling of HTTP SWF file decompression. When the non-default swf-decompression feature is enabled with an unsafe decompression depth, the system may allocate memory incorrectly, allowing crafted SWF responses to exploit this flaw. As a result, the system can crash, potentially disrupting network monitoring and security functionalities. Users are advised to upgrade to versions 8.0.6 and 7.0.17 or later to mitigate this issue.

Affected Version(s)

suricata >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6

suricata < 7.0.17 < 7.0.17

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.