๐Ÿ” CVE Alert

CVE-2026-57225

LOW 3.3

Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6.

CWE CWE-476
Vendor oisf
Product suricata
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for oisf suricata

Be the first to know when new low vulnerabilities affecting oisf suricata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

OISF / suricata
>= 8.0.0, < 8.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OISF/suricata/security/advisories/GHSA-vqqx-88xw-qqvc github.com: https://github.com/OISF/suricata/pull/15699 github.com: https://github.com/OISF/suricata/commit/3ca2ed25a324597a85a2ab11595c3b0689468ea5 github.com: https://github.com/OISF/suricata/commit/bd3293aca714f5d090b73e7d9be0e5cd7e3f5f53 github.com: https://github.com/OISF/suricata/releases/tag/suricata-8.0.6 redmine.openinfosecfoundation.org: https://redmine.openinfosecfoundation.org/issues/8624