Oisf Oisf

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Oisf product.

RSS Feeds for Oisf security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Oisf products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Oisf Sorted by Most Security Vulnerabilities since 2018

Oisf Suricata99 vulnerabilities

Oisf Libhtp6 vulnerabilities

Oisf Suricata Update1 vulnerability

By the Year

In 2026 there have been 48 vulnerabilities in Oisf with an average score of 6.6 out of ten. Last year, in 2025 Oisf had 22 security vulnerabilities published. That is, 26 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.35




Year Vulnerabilities Average Score
2026 48 6.61
2025 22 6.96
2024 20 7.06
2023 3 8.27
2022 0 0.00
2021 3 8.27
2020 1 0.00
2019 7 7.50
2018 1 7.80

It may take a day or so for new Oisf vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Oisf Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-94084 Sep 20, 2026
Suricata <8.0.7 Http2ThreadMultiBuf use-after-free Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
Suricata
CVE-2026-94083 Sep 20, 2026
Suricata <8.0.7 DoH2 type confusion leads to invalid free Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
Suricata
CVE-2026-71855 Sep 18, 2026
Suricata src/flow-hash.c Bypass via IPv4/IPv6 Miscompare pre 7.0.17/8.0.6 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.
Suricata
CVE-2026-71418 Sep 18, 2026
Suricata 8.0.0-8.0.6 DNS-over-HTTP/2 buffer reuse leads to quadratic CPU & DoS Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.
Suricata
CVE-2026-57223 Sep 18, 2026
Suricata <7.0.17 / <8.0.6 Windows Service LPE via Unquoted ImagePath Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.0.6 and 7.0.17.
Suricata
CVE-2026-63446 Sep 18, 2026
Suricata 8.0.0-8.0.5 Unbounded Flow-List Causing CPU & Mem Exhaustion Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transactions remain unmarked, are never freed, and are repeatedly rescanned. The per-flow list can grow without bound with quadratic cleanup cost, causing CPU and memory exhaustion. This issue is fixed in version 8.0.6.
Suricata
CVE-2026-63447 Sep 18, 2026
Suricata app-layer-ftp DoS via Alloc Overrun before 8.0.6 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8.0.6.
Suricata
CVE-2026-63448 Sep 18, 2026
Suricata SMB Parser Unbounded State Exhaustion <7.0.17/8.0.6 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
Suricata
CVE-2026-57229 Sep 18, 2026
Suricata 8.0.0-8.0.6 SMTP MIME state reset flaw leaks data Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6.
Suricata
CVE-2026-57225 Sep 18, 2026
Null pointer deref in Suricata 8.0.0-8.0.6 datasets-context-json.c Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6.
Suricata
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.