Heap Buffer Overflow in Suricata Network Security Monitoring Engine
CVE-2026-63451
3.3LOW
What is CVE-2026-63451?
A heap buffer overflow vulnerability exists in Suricata, a prominent network security monitoring engine. This issue arises from a locally supplied detection rule that improperly combines frame inspection without content and a transformed match without content. The flaw allows for the selection of multiple non-prefilter frame engines during the signature preparation for non-prefilter inspection. Notably, this vulnerability cannot be triggered by external network traffic but can occur when a crafted rule is loaded, even in test mode. The issue has been addressed in Suricata version 8.0.6.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6
