Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oisf

First CVE: May 30, 2014Active for: 12 yearsTotal CVEs: 73
46.1
VTI Score
High

Oisf maintains Suricata, a widely deployed open-source network intrusion detection and prevention engine that sits in line with traffic inspection and threat monitoring workloads across both enterprise and specialized security deployments. Despite a narrow product portfolio, the vendor's prominence in the security landscape derives from Suricata's deep integration into network monitoring infrastructure and its role as a foundational component in threat-detection pipelines. Vulnerabilities affecting the vendor center on resource-handling and memory-safety issues—including unbounded resource consumption, out-of-bounds writes, and NULL-pointer dereferences—that reflect the demands of high-performance packet processing and protocol parsing in a C-based codebase. The recurring exposure across Suricata itself and its companion tools such as libhtp and update utilities underscores the breadth of the attack surface introduced by a protocol-heavy engine exposed to untrusted network input. Live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
73
Total CVEs
More Total CVEs than 99% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oisf over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2014
12 years ago
Most Recent CVE
Apr 2, 2026
113 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22262CRITICAL
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is
Jan 27, 20269.831NONO
CVE-2018-10244CRITICAL
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in
Apr 4, 20199.831NONO
CVE-2021-37592CRITICAL
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.
Nov 19, 20219.830NONO
CVE-2018-10243CRITICAL
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
Apr 4, 20199.829NONO
CVE-2019-18792CRITICAL
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is inject
Jan 6, 20209.128NONO
CVE-2026-31932HIGH
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched i
Apr 2, 20267.527NONO
CVE-2026-31937HIGH
Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in versi
Apr 2, 20267.526NONO
CVE-2026-31935HIGH
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in t
Apr 2, 20267.526NONO
CVE-2026-31934HIGH
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages ov
Apr 2, 20267.526NONO
CVE-2026-31933HIGH
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. Thi
Apr 2, 20267.526NONO
View all 73 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products73 CVEs
16%
74%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (8.2%)
Network66 (90.4%)
Unknown1 (1.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low71 (97.3%)
High1 (1.4%)
Unknown1 (1.4%)
User Interaction
None70 (95.9%)
Unknown1 (1.4%)
Required2 (2.7%)
Privileges Required
Low3 (4.1%)
High0 (0.0%)
None69 (94.5%)
Unknown1 (1.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (73 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oisf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oisf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oisf's Products

View all 4 CNAs →

Top CWEs