CVE-2026-22260
EUVD-2026-479327.01.2026, 18:15
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values for `request-body-limit` and `response-body-limit`.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| oisf | suricata | 8.0.0 ≤ 𝑥 < 8.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
- CWE-674 - Uncontrolled RecursionThe product does not properly control the amount of recursion which takes place, consuming excessive resources, such as allocated memory or the program stack.
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.