Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45763— Suricata lua: sandbox allocation limit not enforced for new allocations

Quick assessment

Affected
OISF suricata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Suricata 是一款网络入侵检测系统(IDS)、入侵防御系统(IPS)以及网络安全监控引擎。从版本 8.0.0 开始至 8.0.5 之前的版本中,当启用 Lua 规则执行时,Lua 沙箱的内存限制对新内存分配未得到一致地强制执行。某些 Lua 内存分配模式可能会超出 的设定值,却未触发预期的内存限制,导致所配置沙箱限制不可靠。该问题需要启用 Lua 规则并加载了受影响的 Lua 脚本/规则。版本 8.0.5 已包含修复。作为临时解决方案,除非确需使用 Lua 规则,否则应禁用 。

CVSS 5.9 · Medium EPSS 0.09% · P25

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45763

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Suricata lua: sandbox allocation limit not enforced for new allocations
Source: CVE Program / CVE List V5
Vulnerability Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory limit was not consistently enforced for new allocations. Certain Lua allocation patterns could exceed `security.lua.max-bytes` without triggering the intended memory limit, making the configured sandbox limit unreliable. This requires Lua rules to be enabled and an affected Lua script/rule to be loaded. Version 8.0.5 contains a fix. As a workaround, disable `security.lua.allow-rules` unless Lua rules are required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OISF suricata >= 8.0.0, < 8.0.5 -

II. Public POCs for CVE-2026-45763

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45763

登录查看更多情报信息。

Vendor Advisories for CVE-2026-45763 (1)

Vendor Pages for CVE-2026-45763 (1)

Other References for CVE-2026-45763 (1)

Same Patch Batch · OISF · 2026-09-10 · 3 CVEs total

CVE-2026-45747 7.5 HIGH Suricata lua/tls: null dereference in TlsGetCertInfo
CVE-2026-46387 7.5 HIGH Suricata http2: decompression bomb can cause denial of service in Suricata

IV. Related Vulnerabilities

V. Comments for CVE-2026-45763

No comments yet


Leave a comment