---
id: CVE-2026-45765
title: >-
  Suricata is a network Intrusion Detection System, Intrusion Prevention System
  and Network Security Monitoring engine
summary: >-
  Suricata is a network Intrusion Detection System, Intrusion Prevention System
  and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,
  DNP3 reassembly could buffer data without sufficient parser-level bounds.
  Crafted D…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: oisf
product: suricata
affected:
  - 'suricata >= 7.0.0, < 7.0.16'
  - 'suricata >= 8.0.0, < 8.0.5'
patched:
  - suricata 8.0.5
published: '2026-09-10'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:18:06.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45765'
references:
  - url: 'https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315'
    label: security-advisories@github.com
  - url: 'https://github.com/OISF/suricata/security/advisories/GHSA-m8x4-c78g-r4vj'
    label: security-advisories@github.com
  - url: 'https://redmine.openinfosecfoundation.org/issues/8460'
    label: security-advisories@github.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45765.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-45765'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-45765'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45765'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00432
epssPercentile: 0.36984
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T17:41:01.835861Z'
ingestedAt: '2026-09-14T00:35:28.535Z'
---

## Overview

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted DNP3 traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable DNP3 (which is not enabled by default) if it is not needed, and/or define a limited `stream.reassembly.depth` (0 or absent is unlimited).

## Affected

- `suricata >= 7.0.0, < 7.0.16`
- `suricata >= 8.0.0, < 8.0.5`

## Remediation

Upgrade past the affected range:

- `suricata 8.0.5`

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45765.json)
