Oisf Security Vulnerabilities (CVEs)

Track 29 security vulnerabilities affecting Oisf products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

2 Critical
23 High
4 Medium
🔔 Get Alerts for Oisf
CVE-2025-64344 7.5

A stack overflow vulnerability in Suricata's Lua scripting engine allows attackers to cause denial of service or potentially execute arbitrary code by...

Nov 26, 2025
CVE-2025-64330 7.5

A heap overflow vulnerability in Suricata's logging functionality can cause crashes when specific alert queue conditions are met. This affects Suricat...

Nov 26, 2025
CVE-2025-64332 7.5

A stack overflow vulnerability in Suricata's SWF decompression feature can cause the IDS/IPS engine to crash when processing malicious SWF files. This...

Nov 26, 2025
CVE-2025-64334 7.5

This vulnerability in Suricata allows an attacker to cause unbounded memory growth by sending specially crafted compressed HTTP data, potentially lead...

Nov 26, 2025
CVE-2025-59150 7.5

A NULL pointer dereference vulnerability in Suricata's TLS subject alternative name parsing causes segmentation faults when processing malicious TLS c...

Oct 1, 2025
CVE-2025-59147 7.5

CVE-2025-59147 is a detection bypass vulnerability in Suricata where crafted traffic with multiple SYN packets containing different sequence numbers w...

Oct 1, 2025
CVE-2025-59149 6.2

A stack buffer overflow vulnerability in Suricata versions 8.0.0 allows attackers to potentially execute arbitrary code or cause denial of service. Th...

Oct 1, 2025
CVE-2025-53538 7.5

A memory handling vulnerability in Suricata's HTTP/2 parser allows uncontrolled memory consumption when processing data on stream 0. This can lead to ...

Jul 22, 2025
CVE-2025-29917 6.2

Suricata's decode_base64 keyword has insufficient memory allocation limits, allowing attackers to trigger excessive memory consumption up to 4GB per t...

Apr 10, 2025
CVE-2025-29915 7.5

Suricata's default AF_PACKET defrag configuration causes packet truncation when reassembling fragmented packets, leading to incomplete network traffic...

Apr 10, 2025
CVE-2024-55629 7.5

This vulnerability in Suricata allows attackers to evade detection by using TCP urgent data (out-of-band data) to make Suricata analyze network traffi...

Jan 6, 2025
CVE-2024-55627 5.9

This vulnerability in Suricata allows an attacker to trigger a large buffer overflow via specially crafted TCP streams, potentially leading to denial ...

Jan 6, 2025
CVE-2024-55628 7.5

This vulnerability in Suricata allows attackers to send specially crafted DNS messages with compressed resource names that can cause excessive resourc...

Jan 6, 2025
CVE-2024-55605 7.5

This vulnerability in Suricata allows attackers to cause a denial-of-service by sending specially crafted network traffic that triggers a stack overfl...

Jan 6, 2025
CVE-2024-45797 7.5

CVE-2024-45797 is a resource exhaustion vulnerability in LibHTP, a widely-used HTTP parser library. Attackers can send specially crafted HTTP requests...

Oct 16, 2024
CVE-2024-47188 7.5

CVE-2024-47188 is a denial-of-service vulnerability in Suricata's thash implementation where missing random seed initialization allows attackers to pr...

Oct 16, 2024
CVE-2024-45795 7.5

This vulnerability in Suricata allows an attacker to cause a denial of service by triggering an assertion failure when rules use datasets with the uni...

Oct 16, 2024
CVE-2024-38534 7.5

CVE-2024-38534 is a denial-of-service vulnerability in Suricata where specially crafted Modbus traffic can cause unlimited resource accumulation withi...

Jul 11, 2024
CVE-2024-38536 7.5

A memory allocation failure in Suricata's HTTP inspection module leads to a NULL pointer dereference and crash when the http.memcap limit is reached. ...

Jul 11, 2024
CVE-2024-32867 5.3

This vulnerability in Suricata involves improper handling of IP fragmentation anomalies, which can cause the intrusion detection/prevention system to ...

May 7, 2024
CVE-2024-32663 7.5

CVE-2024-32663 is a memory exhaustion vulnerability in Suricata's HTTP/2 parser where small amounts of HTTP/2 traffic can cause excessive memory consu...

May 7, 2024
CVE-2024-28871 7.5

CVE-2024-28871 is a denial-of-service vulnerability in LibHTP's HTTP parser where malformed request traffic causes excessive CPU usage. This affects a...

Apr 4, 2024
CVE-2024-28870 7.5

Suricata versions before 6.0.17 and 7.0.4 are vulnerable to a denial-of-service attack when processing excessively long SSH banners. Attackers can cau...

Apr 3, 2024
CVE-2024-23839 7.1

CVE-2024-23839 is a heap use-after-free vulnerability in Suricata's HTTP header parsing. Attackers can cause memory corruption and potential code exec...

Feb 26, 2024
CVE-2024-23836 7.5

CVE-2024-23836 is a resource exhaustion vulnerability in Suricata where attackers can craft malicious network traffic to cause excessive CPU and memor...

Feb 26, 2024
CVE-2023-35852 7.5

This vulnerability allows an attacker who controls external Suricata rules to perform directory traversal attacks, potentially writing arbitrary files...

Jun 19, 2023
CVE-2023-35853 9.8

This vulnerability allows an adversary who controls an external source of Lua rules to execute arbitrary Lua code in Suricata. It affects Suricata ins...

Jun 19, 2023
CVE-2021-45098 7.5

This vulnerability allows attackers to bypass HTTP-based intrusion detection signatures in Suricata by sending a crafted RST TCP packet with random TC...

Dec 16, 2021
CVE-2021-37592 9.8

This vulnerability allows attackers to evade Suricata's TCP traffic inspection by sending a crafted sequence of TCP segments from a malicious client. ...

Nov 19, 2021

Why Monitor Oisf Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 29+ known vulnerabilities affecting Oisf products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Oisf packages in under 60 seconds. No agents required - completely agentless scanning that works across Oisf deployments.

Free vulnerability database: Access detailed information about every Oisf CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Oisf CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Oisf CVEs Free