These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, allows a Lua rule to corrupt Lua detection state and potentially bypass the restricted Lua sandbox if too many flow variables are registered. This issue affects Suricata versions 8.0.0 through 8.0.4 and can cause Suricata to crash. A fix is available in version 8.0.5. As [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an attacker to cause a denial of service by consuming excessive memory through repeated crafted UDP traffic. The issue is fixed in versions 7.0.16 and 8.0.5. This vulnerability affects network security monitoring and intrusion detection capabilities, requiring [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an attacker to cause excessive memory consumption, potentially resulting in a denial of service. The issue, which affects Suricata versions 8.0.0 through 8.0.4, is due to the LDAP transaction state storing an unbounded number of responses. This can be exploite [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow a malicious rule to potentially overwrite any file on the file system on rule load or reload. This issue is addressed in versions 7.0.16 and 8.0.5. The vulnerability has a medium CVSS score of 4.4, indicating a moderate severity level. Network security teams u [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, allows crafted NFS traffic to cause excessive memory consumption, potentially leading to denial of service. The issue is fixed in versions 7.0.16 and 8.0.5. This vulnerability is particularly concerning because it can be exploited through specially crafted NFS traffic, wh [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow crafted DNP3 traffic to cause excessive memory consumption, potentially resulting in denial of service. The issue is addressed in versions 7.0.16 and 8.0.5. Defenders should be aware of the potential impact on network security and prioritize updates or workaro [truncated]
A critical vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could lead to a denial of service via crafted HTTP/2 traffic. This CVE was published on 2026-09-10T22:16:56.250Z and was last modified on 2026-09-11T18:24:59.400Z. The vulnerability, tracked as CVE-2026-45764, is due to a type confusion issue caused by a protocol [truncated]
A vulnerability in Suricata's IP defragmentation tracker lookup can lead to a remote packet-triggered crash and denial of service. This issue affects Suricata versions prior to 7.0.16 and 8.0.5. The vulnerability's impact is supported by the CVE record and NVD entry, but further verification is needed to determine the full scope of affected systems and potential exploitation. Network defenders and adminis [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an attacker to cause excessive CPU usage and denial of service via crafted HTTP traffic with large Content-Disposition headers. The issue affects versions prior to 7.0.16 and 8.0.5. A workaround is available using a specific rule.
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an attacker to cause a denial-of-service condition. The issue arises when certain detection transforms are chained, allowing the decompress transform pipeline to read from an inspection buffer after it has been reallocated and freed. This can be triggered by a [truncated]
A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an inspection pointer to reference freed memory after a chained transform caused the backing buffer to be reallocated. This issue is reached during specific network traffic processing and requires a specific but not malicious rule. The vulnerability is address [truncated]