VulnSea

OISF has 35 CVEs on record. Disclosure cadence is accelerating: 35 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 35. The median CVSS is 7.5 (high), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (9) and CWE-770 (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
35 prev 0

Products

  • Suricata 35
35
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

OISF vulnerabilities

CVEs affecting OISF, newest first. Open any entry for full detail, references, and exploit status.

35 CVEsRSS

CVE-2026-45766High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffi…

Twilightoisf · suricataEPSS 0.43%via NVD
CVE-2026-45759High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposit…

Twilightoisf · suricataEPSS 0.58%via NVD
CVE-2026-45769High· 7.5PoC
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeat…

Midnightoisf · suricataEPSS 1.3%via NVD
CVE-2026-45770High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua…

Twilightoisf · suricataEPSS 0.34%via NVD
CVE-2026-45747High· 7.5PoC
1w ago

Suricata lua/tls: null dereference in TlsGetCertInfo

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lu…

MidnightOISF · suricataEPSS 0.34%via CVEORG
OISF vulnerabilities (CVEs) — page 2 · VulnSea