PatchSiren cyber security CVE debrief
CVE-2026-45769 OISF CVE debrief
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an attacker to cause a denial of service by consuming excessive memory through repeated crafted UDP traffic. The issue is fixed in versions 7.0.16 and 8.0.5. This vulnerability affects network security monitoring and intrusion detection capabilities, requiring immediate attention from network defenders and administrators using Suricata to assess exposure and prioritize updates.
- Vendor
- OISF
- Product
- suricata
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-11
Who should care
Network defenders and administrators using Suricata should assess exposure and prioritize updating to versions 7.0.16 or 8.0.5. This vulnerability affects network security monitoring and intrusion detection capabilities, requiring immediate attention from those responsible for maintaining Suricata deployments. Affected operators, platforms, and security teams should review and address this vulnerability to prevent potential denial-of-service attacks.
Why it matters
Defenders should care about this vulnerability as it could allow an attacker to cause a denial of service in Suricata, potentially affecting network security monitoring and intrusion detection capabilities. Network defenders and administrators using Suricata should assess exposure and prioritize updating to versions 7.0.16 or 8.0.5. The vulnerability requires verification of affected versions and remediation priority.
- Denial of service through excessive memory consumption
- Potential for repeated crafted UDP traffic to cause Suricata to consume excessive memory
Technical summary
The IKEv2 parser state in Suricata could grow without bounds while storing client transforms, potentially resulting in denial of service through repeated crafted UDP traffic. This issue arises from the parser's inability to limit the number of client transforms, allowing an attacker to cause excessive memory consumption. Network defenders and administrators should be aware of the potential for denial-of-service attacks and take steps to mitigate this vulnerability. The vulnerability is addressed in Suricata versions 7.0.16 and 8.0.5.
Defensive priority
Defenders should prioritize updating Suricata to versions 7.0.16 or 8.0.5 to prevent potential denial of service attacks.
Recommended defensive actions
- Update Suricata to version 7.0.16 or 8.0.5
- Disable IKE application-layer parsing if not needed
- Use a rule to bypass IKE flows after the first packets
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability requires verification of affected versions and remediation priority. Network defenders should verify Suricata version deployments and assess potential exposure to this denial-of-service vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45769 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45769
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45769 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45769
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
-
Source reference
Unverified legacy reference
URL: https://github.com/OISF/suricata/security/advisories/GHSA-hg2g-r464-5593
-
Source reference
Unverified legacy reference
URL: https://redmine.openinfosecfoundation.org/issues/8415
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.