Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OISF — Vulnerabilities & Security Advisories 90

Browse all 90 CVE security advisories affecting OISF. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Open Information Security Foundation (OISF) develops and maintains Suricata, an open-source network intrusion detection and prevention system widely deployed for real-time traffic analysis. With fifty-five recorded Common Vulnerabilities and Exposures, the organization’s software has historically been susceptible to remote code execution, buffer overflow, and denial-of-service flaws, often stemming from complex packet parsing logic. These vulnerabilities occasionally allow attackers to crash the service or execute arbitrary commands on affected hosts. While no catastrophic data breaches directly attributed to OISF have been publicly documented, the high volume of CVEs highlights the inherent risks in maintaining large-scale, C-based security infrastructure. The foundation addresses these issues through regular updates and community-driven patching, emphasizing transparency in its security response process.

Top products by OISF: suricata libhtp
CVE ID Title CVSS Severity Published
CVE-2026-45752 Suricata detect/transform: use-after-free in decompress transforms — suricata CWE-416 5.9 Medium 2026-09-10
CVE-2026-45751 Suricata detect/transform: use-after-free in dotprefix transform — suricata CWE-416 5.9 Medium 2026-09-10
CVE-2026-45747 Suricata lua/tls: null dereference in TlsGetCertInfo — suricata CWE-476 7.5 High 2026-09-10
CVE-2026-46387 Suricata http2: decompression bomb can cause denial of service in Suricata — suricata CWE-409 7.5 High 2026-09-10
CVE-2026-45763 Suricata lua: sandbox allocation limit not enforced for new allocations — suricata CWE-770 5.9 Medium 2026-09-10
CVE-2026-31937 Suricata dcerpc: quadratic complexity in dcerpc buffering — suricata CWE-407 7.5 High 2026-04-02
CVE-2026-31935 Suricata http2: unbounded resource consumption — suricata CWE-400 7.5 High 2026-04-02
CVE-2026-31934 Suricata smtp/mine: quadratic complexity in extracting urls — suricata CWE-407 7.5 High 2026-04-02
CVE-2026-31933 Suricata stream: quadratic complexity in stream inspection — suricata CWE-407 7.5 High 2026-04-02
CVE-2026-31932 Suricata krb5: quadratic complexity in krb5 buffering — suricata CWE-407 7.5 High 2026-04-02
CVE-2026-31931 Suricata tls: null dereference in tls.alpn rule keyword — suricata CWE-476 7.5 High 2026-04-02
CVE-2026-22264 Suricata detect/alert: heap-use-after-free on alert queue expansion — suricata CWE-416 7.4 High 2026-01-27
CVE-2026-22263 Suricata http1: quadratic complexity in headers parsing over multiple packets — suricata CWE-1050 5.3 Medium 2026-01-27
CVE-2026-22262 Suricata datasets: stack overflow when saving a set — suricata CWE-121 5.9 Medium 2026-01-27
CVE-2026-22261 Suricata eve/alert: http1 xff handling can lead to denial of service — suricata CWE-1050 3.7 Low 2026-01-27
CVE-2026-22260 Suricata http1: infinite recursion in decompression — suricata CWE-674 7.5 High 2026-01-27
CVE-2026-22259 Suricata dnp3: unbounded transaction growth — suricata CWE-400 7.5 High 2026-01-27
CVE-2026-22258 Suricata DCERPC: unbounded fragment buffering leads to memory exhaustion — suricata CWE-400 7.5 High 2026-01-27
CVE-2025-64344 Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer — suricata CWE-121 7.5 High 2025-11-26
CVE-2025-64330 Suricata is vulnerable to a heap buffer overflow on verdict — suricata CWE-122 7.5 High 2025-11-26
CVE-2025-64331 Suricata is vulnerable to a stack overflow on large file transfers with http-body-printable — suricata CWE-121 7.5 High 2025-11-26
CVE-2025-64332 Suricata is vulnerable to a stack overflow on larger compressed data — suricata CWE-121 7.5 High 2025-11-26
CVE-2025-64333 Suricata is vulnerable to a stack overflow from big content-type — suricata CWE-121 7.5 High 2025-11-26
CVE-2025-64335 Suricata is vulnerable to a null deref when used with base64_data — suricata CWE-476 7.5 High 2025-11-26
CVE-2025-64334 Suricata is vulnerable to unbounded memory growth for decompression — suricata CWE-770 7.5 High 2025-11-26
CVE-2025-59150 Suricata: Keyword tls.subjectaltname can lead to NULL-ptr deref — suricata CWE-476 7.5 High 2025-10-01
CVE-2025-59149 Suricata: Stack buffer overflow in rule parser when processing long keywords with transforms — suricata CWE-121 6.2 Medium 2025-10-01
CVE-2025-59148 Suricata's improper use of entropy keyword can lead to a NULL-ptr deref — suricata CWE-476 7.5 High 2025-10-01
CVE-2025-59147 Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN Packets — suricata CWE-358 7.5 High 2025-10-01
CVE-2025-53537 LibHTP's memory leak with lzma can lead to resource starvation — libhtp CWE-401 7.5 High 2025-07-23

This page lists every published CVE security advisory associated with OISF. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.