Oisf maintains Suricata, a widely deployed open-source network intrusion detection and prevention engine that sits in line with traffic inspection and threat monitoring workloads across both enterprise and specialized security deployments. Despite a narrow product portfolio, the vendor's prominence in the security landscape derives from Suricata's deep integration into network monitoring infrastructure and its role as a foundational component in threat-detection pipelines. Vulnerabilities affecting the vendor center on resource-handling and memory-safety issues—including unbounded resource consumption, out-of-bounds writes, and NULL-pointer dereferences—that reflect the demands of high-performance packet processing and protocol parsing in a C-based codebase. The recurring exposure across Suricata itself and its companion tools such as libhtp and update utilities underscores the breadth of the attack surface introduced by a protocol-heavy engine exposed to untrusted network input. Live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oisf over time
Signals from CVEs in this vendor scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22262CRITICAL Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is | Jan 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2018-10244CRITICAL Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in | Apr 4, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-37592CRITICAL Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments. | Nov 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-10243CRITICAL htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header. | Apr 4, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-18792CRITICAL An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is inject | Jan 6, 2020 | 9.1 | 28 | NO | NO |
CVE-2026-31932HIGH Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched i | Apr 2, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-31937HIGH Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in versi | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31935HIGH Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in t | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31934HIGH Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages ov | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31933HIGH Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. Thi | Apr 2, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (73 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oisf.
Media articles that mention a CVE ID that affects a product developed by Oisf — matched by CVE ID, not by vendor name.