CVE-2026-22260

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values for `request-body-limit` and `response-body-limit`.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

29 Jan 2026, 21:03

Type Values Removed Values Added
CWE CWE-787
References () https://github.com/OISF/suricata/commit/0dddac7278c8b9cf3c1e4c1c71e620a78ec1c185 - () https://github.com/OISF/suricata/commit/0dddac7278c8b9cf3c1e4c1c71e620a78ec1c185 - Patch
References () https://github.com/OISF/suricata/security/advisories/GHSA-3gm8-84cm-5x22 - () https://github.com/OISF/suricata/security/advisories/GHSA-3gm8-84cm-5x22 - Vendor Advisory
References () https://redmine.openinfosecfoundation.org/issues/8185 - () https://redmine.openinfosecfoundation.org/issues/8185 - Permissions Required
First Time Oisf
Oisf suricata
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

27 Jan 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 18:15

Updated : 2026-01-29 21:03


NVD link : CVE-2026-22260

Mitre link : CVE-2026-22260

CVE.ORG link : CVE-2026-22260


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-674

Uncontrolled Recursion

CWE-787

Out-of-bounds Write