PatchSiren cyber security CVE debrief
CVE-2026-45770 OISF CVE debrief
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, allows a Lua rule to corrupt Lua detection state and potentially bypass the restricted Lua sandbox if too many flow variables are registered. This issue affects Suricata versions 8.0.0 through 8.0.4 and can cause Suricata to crash. A fix is available in version 8.0.5. As a workaround, users can disable `security.lua.allow-rules` if Lua rules are not required.
- Vendor
- OISF
- Product
- suricata
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-11
Who should care
Network defenders and administrators using Suricata for intrusion detection and prevention should assess their exposure and prioritize patching or applying workarounds. This includes reviewing Suricata configurations, verifying affected versions, and updating to version 8.0.5 or applying the workaround by disabling `security.lua.allow-rules` if Lua rules are not necessary. Operators, platform administrators, vulnerability management teams, and security squ
Why it matters
Defenders should care about CVE-2026-45770 because it affects Suricata, a widely used network Intrusion Detection System. The vulnerability can lead to a bypass of the restricted Lua sandbox and cause system crashes if exploited. Network defenders and administrators should assess their exposure, especially if they use Lua rules or have not updated Suricata to version 8.0.5. The evidence is based on official CVE and NVD records, which provide details on the vulnerability and the available fix.
- Potential bypass of Suricata's restricted Lua sandbox
- Suricata crash due to excessive flow variables
- Need for verification of affected versions and Lua rule usage
- Priority for patching or applying workarounds
Technical summary
The vulnerability in Suricata allows a Lua rule that registers too many flow variables to corrupt Lua detection state. This can potentially bypass Suricata's restricted Lua sandbox and cause Suricata to crash. The issue affects Suricata versions 8.0.0 through 8.0.4 and is resolved in Suricata version 8.0.5. Network defenders and administrators should assess their exposure, especially if they use Lua rules or have not updated Suricata to version 8.0.5. As a workaround, users can disable `security.lua.allow-rules` if Lua rules are not necessary.
Defensive priority
Defenders should prioritize patching to version 8.0.5 or applying the workaround by disabling `security.lua.allow-rules` if Lua rules are not necessary.
Recommended defensive actions
- Patch Suricata to version 8.0.5
- Disable `security.lua.allow-rules` if Lua rules are not required
- Review and update Suricata configurations to prevent excessive flow variables in Lua rules
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, its impact, and the available fix. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information, requiring verification from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45770 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45770
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45770 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45770
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
-
Source reference
Unverified legacy reference
URL: https://github.com/OISF/suricata/security/advisories/GHSA-653j-cc95-vj4c
-
Source reference
Unverified legacy reference
URL: https://redmine.openinfosecfoundation.org/issues/8556
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.