PatchSiren cyber security CVE debrief
CVE-2026-45766 OISF CVE debrief
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, allows crafted NFS traffic to cause excessive memory consumption, potentially leading to denial of service. The issue is fixed in versions 7.0.16 and 8.0.5. This vulnerability is particularly concerning because it can be exploited through specially crafted NFS traffic, which could be a common occurrence in network environments. Network defenders and security teams should assess their exposure and prioritize updating to the fixed versions to prevent potential denial of service attacks. Suricata's role in network security monitoring and intrusion is
- Vendor
- OISF
- Product
- suricata
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-11
Who should care
Network defenders and security teams responsible for managing Suricata installations should assess their exposure and prioritize updating to the fixed versions to prevent potential denial of service attacks. This is particularly important for environments where Suricata is used for network security monitoring and intrusion detection/prevention.
Why it matters
CVE-2026-45766 is a high-severity vulnerability in Suricata that can lead to denial of service via crafted NFS traffic. Network defenders and security teams should assess their exposure, prioritize updates to versions 7.0.16 or 8.0.5, and consider temporary workarounds like disabling NFS application-layer parsing if immediate updates are not feasible. The corpus provides details on the vulnerability and fixes but does not establish versions, exploitation, impact, or remediation beyond the provided information, requiring verification from official sources.
- Denial of service via excessive memory consumption
- Potential network security monitoring and intrusion detection/prevention service disruption
- Need for verification of affected versions and exposure
- Priority for updating or applying workarounds
Technical summary
The Suricata engine, used for network Intrusion Detection, Intrusion Prevention, and Network Security Monitoring, has a vulnerability in its NFS parser state structures. These structures are insufficiently bounded, allowing crafted NFS traffic to cause Suricata to consume excessive memory. This excessive memory consumption can lead to a denial of service. The vulnerability is addressed in Suricata versions 7.0.16 and 8.0.5. As a temporary workaround, disabling NFS application-layer parsing can mitigate the risk if updating is not immediately feasible.
Defensive priority
Defenders should prioritize updating Suricata to versions 7.0.16 or 8.0.5 to prevent potential denial of service attacks. If immediate updates are not feasible, disabling NFS application-layer parsing may serve as a temporary workaround.
Recommended defensive actions
- Update Suricata to version 7.0.16 or 8.0.5
- Disable NFS application-layer parsing if not needed
- Monitor for unusual NFS traffic patterns
- Review Suricata configurations for potential vulnerabilities
- Perform an inventory of assets using Suricata for exposure review
- Consider compensating controls for exposed systems while remediation is scheduled
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and available fixes. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information, requiring verification from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45766 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45766
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45766 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45766
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
-
Source reference
Unverified legacy reference
URL: https://github.com/OISF/suricata/security/advisories/GHSA-jqr4-ch38-wvm6
-
Source reference
Unverified legacy reference
URL: https://redmine.openinfosecfoundation.org/issues/8418
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.