๐Ÿ” CVE Alert

CVE-2026-57228

HIGH 8.2

Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape sequence is split across traffic chunks and the following chunk contains exactly one byte. Crafted SMTP traffic can trigger the out-of-bounds read and crash Suricata when decode-quoted-printable MIME decoding is enabled. This issue is fixed in version 7.0.17.

CWE CWE-125
Vendor oisf
Product suricata
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for oisf suricata

Be the first to know when new high vulnerabilities affecting oisf suricata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High

Affected Versions

OISF / suricata
>= 7.0.13, < 7.0.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OISF/suricata/security/advisories/GHSA-qxm4-q7vx-7xj4 github.com: https://github.com/OISF/suricata/commit/19880f9d5bbe2b8f8e8867a577848dce2b532c86 github.com: https://github.com/OISF/suricata/releases/tag/suricata-7.0.17 redmine.openinfosecfoundation.org: https://redmine.openinfosecfoundation.org/issues/8608