๐Ÿ” CVE Alert

CVE-2026-63451

LOW 3.3

Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, a locally supplied detection rule that combines frame inspection without content and a transformed match without content can make src/detect-engine-prefilter.c select multiple non-prefilter frame engines while preparing signatures for non-prefilter inspection. Loading the crafted rule, including in test mode, can trigger a heap buffer overflow and crash Suricata; network traffic alone cannot reach the flaw. This issue is fixed in version 8.0.6.

CWE CWE-122
Vendor oisf
Product suricata
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for oisf suricata

Be the first to know when new low vulnerabilities affecting oisf suricata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

OISF / suricata
>= 8.0.0, < 8.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OISF/suricata/security/advisories/GHSA-6qwq-j83r-qp34 github.com: https://github.com/OISF/suricata/pull/15807 github.com: https://github.com/OISF/suricata/commit/5449ae170bfce213907d9bab87143a59774ed48f github.com: https://github.com/OISF/suricata/commit/d62acf5d75a61b76b16815e773408852f41b1975 github.com: https://github.com/OISF/suricata/releases/tag/suricata-8.0.6 redmine.openinfosecfoundation.org: https://redmine.openinfosecfoundation.org/issues/8590