{"id":"CVE-2026-45766","title":"Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine","summary":"Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffi…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770"],"vendor":"oisf","product":"suricata","affected":["suricata >= 7.0.0, < 7.0.16","suricata >= 8.0.0, < 8.0.5"],"patched":["suricata 8.0.5"],"published":"2026-09-10","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:18:22.197","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45766","references":[{"url":"https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315","label":"security-advisories@github.com"},{"url":"https://github.com/OISF/suricata/security/advisories/GHSA-jqr4-ch38-wvm6","label":"security-advisories@github.com"},{"url":"https://redmine.openinfosecfoundation.org/issues/8418","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45766.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-45766"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45766"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45766"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00432,"epssPercentile":0.36985,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-11T14:43:21.392634Z"},"ingestedAt":"2026-09-12T13:43:50.966Z","slug":"CVE-2026-45766","body":"## Overview\n\nSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS application-layer parsing if it is not needed.\n\n## Affected\n\n- `suricata >= 7.0.0, < 7.0.16`\n- `suricata >= 8.0.0, < 8.0.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `suricata 8.0.5`\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45766.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}