Suricata
Vendor:
First CVE: May 30, 2014 · Active for 12 years
65
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Suricata over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2014
12 years ago
Most Recent CVE
Apr 2, 2026
117 days ago
CVE Severity & Scoring
Suricata65 CVEs
17%
74%
9%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (7.7%)
Network59 (90.8%)
Unknown1 (1.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (96.9%)
High1 (1.5%)
Unknown1 (1.5%)
User Interaction
None63 (96.9%)
Unknown1 (1.5%)
Required1 (1.5%)
Privileges Required
Low3 (4.6%)
High0 (0.0%)
None61 (93.8%)
Unknown1 (1.5%)
Top CVEs
Signals from CVEs in this product scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22262CRITICAL Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is | Jan 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2018-10244CRITICAL Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in | Apr 4, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-37592CRITICAL Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments. | Nov 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-18792CRITICAL An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is inject | Jan 6, 2020 | 9.1 | 28 | NO | NO |
CVE-2026-31932HIGH Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched i | Apr 2, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-31937HIGH Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in versi | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31935HIGH Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in t | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31934HIGH Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages ov | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31933HIGH Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. Thi | Apr 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-31931HIGH Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. T | Apr 2, 2026 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (65 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (65 CVEs).
Media Mentions
Signals from CVEs in this product scope (65 CVEs).
Top CNAs Publishing CVEs For Suricata
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.0 | 5 | 7.2 | 0.4% | 0 | 0 |
| 5.0.0 | 2 | 8.3 | 2.1% | 0 | 0 |
| 4.1.0 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.0.5 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.0.4 | 2 | 8.7 | 1.6% | 0 | 0 |
| 4.0.3 | 1 | 7.5 | 2.1% | 0 | 0 |
| 4.0.2 | 1 | 7.5 | 2.1% | 0 | 0 |
| 1.4.6 | 1 | 7.5 | 3.5% | 0 | 0 |
| 1.4.4 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.4.3 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.4.2 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.4.1 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.4 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3.6 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3.5 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3.4 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3.3 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3.2 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3.1 | 1 | 5.0 | 1.6% | 0 | 0 |
| 1.3 | 1 | 5.0 | 1.6% | 0 | 0 |