Heap Buffer Overflow in Suricata Network Security Monitoring Engine
CVE-2026-57226
3.7LOW
What is CVE-2026-57226?
Suricata, a well-known network intrusion detection and prevention system, is vulnerable to a heap buffer overflow due to improper handling of HTTP SWF file decompression. When the non-default swf-decompression feature is enabled with an unsafe decompression depth, the system may allocate memory incorrectly, allowing crafted SWF responses to exploit this flaw. As a result, the system can crash, potentially disrupting network monitoring and security functionalities. Users are advised to upgrade to versions 8.0.6 and 7.0.17 or later to mitigate this issue.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6
suricata < 7.0.17 < 7.0.17
