Suricata

Vendor:

First CVE: May 30, 2014 · Active for 12 years

65
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Suricata over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2014
12 years ago
Most Recent CVE
Apr 2, 2026
117 days ago

CVE Severity & Scoring

Suricata65 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local5 (7.7%)
Network59 (90.8%)
Unknown1 (1.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (96.9%)
High1 (1.5%)
Unknown1 (1.5%)
User Interaction
None63 (96.9%)
Unknown1 (1.5%)
Required1 (1.5%)
Privileges Required
Low3 (4.6%)
High0 (0.0%)
None61 (93.8%)
Unknown1 (1.5%)

Top CVEs

Signals from CVEs in this product scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is
Jan 27, 20269.831NONO
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in
Apr 4, 20199.831NONO
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.
Nov 19, 20219.830NONO
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is inject
Jan 6, 20209.128NONO
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched i
Apr 2, 20267.527NONO
Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in versi
Apr 2, 20267.526NONO
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in t
Apr 2, 20267.526NONO
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages ov
Apr 2, 20267.526NONO
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. Thi
Apr 2, 20267.526NONO
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. T
Apr 2, 20267.526NONO

Exploit Exposure

Signals from CVEs in this product scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (65 CVEs).

Media Mentions

Signals from CVEs in this product scope (65 CVEs).

Top CNAs Publishing CVEs For Suricata

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0.057.20.4%00
5.0.028.32.1%00
4.1.017.52.1%00
4.0.517.52.1%00
4.0.428.71.6%00
4.0.317.52.1%00
4.0.217.52.1%00
1.4.617.53.5%00
1.4.415.01.6%00
1.4.315.01.6%00
1.4.215.01.6%00
1.4.115.01.6%00
1.415.01.6%00
1.3.615.01.6%00
1.3.515.01.6%00
1.3.415.01.6%00
1.3.315.01.6%00
1.3.215.01.6%00
1.3.115.01.6%00
1.315.01.6%00