Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OISF — Vulnerabilities & Security Advisories 90

Browse all 90 CVE security advisories affecting OISF. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Open Information Security Foundation (OISF) develops and maintains Suricata, an open-source network intrusion detection and prevention system widely deployed for real-time traffic analysis. With fifty-five recorded Common Vulnerabilities and Exposures, the organization’s software has historically been susceptible to remote code execution, buffer overflow, and denial-of-service flaws, often stemming from complex packet parsing logic. These vulnerabilities occasionally allow attackers to crash the service or execute arbitrary commands on affected hosts. While no catastrophic data breaches directly attributed to OISF have been publicly documented, the high volume of CVEs highlights the inherent risks in maintaining large-scale, C-based security infrastructure. The foundation addresses these issues through regular updates and community-driven patching, emphasizing transparency in its security response process.

Found 86 results / 90 Clear Filters
Top products by OISF: suricata libhtp
CVE ID Title CVSS Severity Published
CVE-2026-94084 Suricata 8.0.7前Http2ThreadMultiBuf释放后使用漏洞 — Suricata CWE-416 9.4 Critical 2026-09-20
CVE-2026-94083 Suricata 8.0.7之前DoH2类型混淆导致DoS — Suricata CWE-843 9.4 Critical 2026-09-20
CVE-2026-71855 Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state — suricata CWE-697 5.9 Medium 2026-09-18
CVE-2026-71418 Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption — suricata CWE-407 7.5 High 2026-09-18
CVE-2026-57223 Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation — suricata CWE-428 7.0 High 2026-09-18
CVE-2026-63446 Suricata app-layer: passed flows can retain transactions, causing resource exhaustion — suricata CWE-401 7.5 High 2026-09-18
CVE-2026-63447 Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption — suricata CWE-407 7.5 High 2026-09-18
CVE-2026-63448 Suricata smb: some SMB flows can cause resource exhaustion — suricata CWE-400 5.9 Medium 2026-09-18
CVE-2026-57229 Suricata smtp/mime: incomplete state reset allows detection bypass — suricata CWE-665 5.3 Medium 2026-09-18
CVE-2026-57225 Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading — suricata CWE-476 3.3 Low 2026-09-18
CVE-2026-63452 Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption — suricata CWE-400 7.5 High 2026-09-18
CVE-2026-63451 Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load — suricata CWE-122 3.3 Low 2026-09-18
CVE-2026-57227 Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages — suricata CWE-400 7.5 High 2026-09-18
CVE-2026-63450 Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection — suricata CWE-755 3.7 Low 2026-09-18
CVE-2026-63449 Suricata sip: large SIP message bodies can evade detection with frame keyword — suricata CWE-197 3.7 Low 2026-09-18
CVE-2026-57228 Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder — suricata CWE-125 8.2 High 2026-09-18
CVE-2026-57224 Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion — suricata CWE-400 6.5 Medium 2026-09-18
CVE-2026-57226 Suricata swf: heap buffer overflow in SWF decompression depth handling — suricata CWE-122 3.7 Low 2026-09-18
CVE-2026-57222 Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6 — suricata CWE-697 5.3 Medium 2026-09-18
CVE-2026-46352 Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock — suricata CWE-833 7.5 High 2026-09-16
CVE-2026-45770 Suricata lua: excessive flow variable registration can bypass sandbox — suricata CWE-693 7.5 High 2026-09-10
CVE-2026-45769 ikev2: unbounded client transform storage can lead to resource exhaustion — suricata CWE-400 7.5 High 2026-09-10
CVE-2026-45768 Suricata ldap: unbounded responses per transaction can lead to resource exhaustion — suricata CWE-400 7.5 High 2026-09-10
CVE-2026-45767 Suricata datasets: save to absolute filename can be bypassed when combined with load command — suricata CWE-22 4.4 Medium 2026-09-10
CVE-2026-45766 Suricata nfs: unbounded stateful structures can lead to resource exhaustion — suricata CWE-400 7.5 High 2026-09-10
CVE-2026-45765 Suricata dnp3: unbounded reassembly can lead to resource exhaustion — suricata CWE-400 7.5 High 2026-09-10
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service — suricata CWE-843 9.1 Critical 2026-09-10
CVE-2026-45762 Suricata defrag: missing address-family check can lead to remote crash — suricata CWE-843 7.5 High 2026-09-10
CVE-2026-45761 Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load — suricata CWE-122 3.3 Low 2026-09-10
CVE-2026-45759 Suricata http1: quadratic Content-Disposition processing can lead to denial of service — suricata CWE-400 7.5 High 2026-09-10

This page lists every published CVE security advisory associated with OISF. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.