Oisf
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Oisf product.
RSS Feeds for Oisf security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Oisf products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Oisf Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 48 vulnerabilities in Oisf with an average score of 6.6 out of ten. Last year, in 2025 Oisf had 22 security vulnerabilities published. That is, 26 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.35
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 48 | 6.61 |
| 2025 | 22 | 6.96 |
| 2024 | 20 | 7.06 |
| 2023 | 3 | 8.27 |
| 2022 | 0 | 0.00 |
| 2021 | 3 | 8.27 |
| 2020 | 1 | 0.00 |
| 2019 | 7 | 7.50 |
| 2018 | 1 | 7.80 |
It may take a day or so for new Oisf vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Oisf Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-94084 | Sep 20, 2026 |
Suricata <8.0.7 Http2ThreadMultiBuf use-after-freeSuricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. |
|
| CVE-2026-94083 | Sep 20, 2026 |
Suricata <8.0.7 DoH2 type confusion leads to invalid freeSuricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions. |
|
| CVE-2026-71855 | Sep 18, 2026 |
Suricata src/flow-hash.c Bypass via IPv4/IPv6 Miscompare pre 7.0.17/8.0.6Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17. |
|
| CVE-2026-71418 | Sep 18, 2026 |
Suricata 8.0.0-8.0.6 DNS-over-HTTP/2 buffer reuse leads to quadratic CPU & DoSSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6. |
|
| CVE-2026-57223 | Sep 18, 2026 |
Suricata <7.0.17 / <8.0.6 Windows Service LPE via Unquoted ImagePathSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low-privileged attacker, Windows can execute an attacker-controlled program as LocalSystem, resulting in local privilege escalation. This issue is fixed in versions 8.0.6 and 7.0.17. |
|
| CVE-2026-63446 | Sep 18, 2026 |
Suricata 8.0.0-8.0.5 Unbounded Flow-List Causing CPU & Mem ExhaustionSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transactions remain unmarked, are never freed, and are repeatedly rescanned. The per-flow list can grow without bound with quadratic cleanup cost, causing CPU and memory exhaustion. This issue is fixed in version 8.0.6. |
|
| CVE-2026-63447 | Sep 18, 2026 |
Suricata app-layer-ftp DoS via Alloc Overrun before 8.0.6Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8.0.6. |
|
| CVE-2026-63448 | Sep 18, 2026 |
Suricata SMB Parser Unbounded State Exhaustion <7.0.17/8.0.6Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17. |
|
| CVE-2026-57229 | Sep 18, 2026 |
Suricata 8.0.0-8.0.6 SMTP MIME state reset flaw leaks dataSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6. |
|
| CVE-2026-57225 | Sep 18, 2026 |
Null pointer deref in Suricata 8.0.0-8.0.6 datasets-context-json.cSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6. |
|