Suricata 7 has reached EOL meaning no more bug fixes, security updates, or maintenance releases.
We recommend upgrading to #Suricata 8 and staying current with the latest patch release.
Read the EOL policy: suricata.io/our-story/eo...

Suricata 7 has reached EOL meaning no more bug fixes, security updates, or maintenance releases.
We recommend upgrading to #Suricata 8 and staying current with the latest patch release.
Read the EOL policy: suricata.io/our-story/eo...
Open-source security tools are only as resilient as the components underneath them. That's why OISF is working with Konstantinos Margaritis and @VectorCamp on a 6-month pilot to support #Vectorscan, the pattern-matching library at the heart of #Suricata's performance.
suricata.io/2026/09/29/w...
CVE-2026-57229 Suricata SMTP MIME parser state leak lets crafted mail evade file.data, file.name and URL detections. CVSS 5.3, no patch yet. Isolate or review SMTP MIME decoding now. https://www.valtersit.com/cve/CVE-2026-57229/ #CVE #Suricata #infosec
CVE-2026-63450 Suricata FTP parser: pre-negotiation RETR/STOR kills parsing for the TCP flow, letting later commands evade parser-dependent rules and logging. CVSS 3.7, unpatched. Update to 8.0.6 now. https://www.valtersit.com/cve/CVE-2026-63450/ #CVE #infosec #Suricata
CVE-2026-71418: Suricata DoS, CVSS 7.5. DNS-over-HTTP/2 buffer flaw causes quadratic CPU use, degrading packet processing. Unpatched as of now - update immediately. https://www.valtersit.com/cve/CVE-2026-71418/ #CVE #Suricata #infosec
CVE-2026-63452 Suricata DoS: brotli compression bombs exhaust the HTTP/1 parser, degrading packet processing. CVSS 7.5, no patch yet. Update immediately. https://www.valtersit.com/cve/CVE-2026-63452/ #CVE #infosec #Suricata
CVE-2026-57228 Suricata out-of-bounds read in SMTP quoted-printable decoder. CVSS 8.2. Crafted traffic crashes the IDS. No patch yet. Isolate or disable decode-quoted-printable. https://www.valtersit.com/cve/CVE-2026-57228/ #CVE #infosec #Suricata
CVE-2026-63446 Suricata 8.0.0-8.0.6: inverted guard in AppLayerParserSetTransactionInspectId() skips detection on pass-rule flows. Unfreed transactions rescan endlessly, risking memory exhaustion/DoS. CVSS 7.5, unpatched. Update https://www.valtersit.com/cve/CVE-2026-63446/ #CVE #infosec #Suricata
Suricata carries a D trust score with 27 CVEs, 17 high severity, and 100% still unpatched. No KEV exploits yet, but that open gap is the risk. https://www.valtersit.com/vendors/suricata/ #cybersecurity #infosec #Suricata
CVE-2026-63447: Suricata FTP parser DoS, CVSS 7.5. Crafted FTP traffic causes quadratic processing that degrades packet inspection. No patch yet. Apply mitigations and watch for updates. https://www.valtersit.com/cve/CVE-2026-63447/ #CVE #infosec #Suricata
CVE-2026-57227 Suricata MQTT parser DoS, CVSS 7.5. Unbounded PUBREC/PUBREL floods grow transaction state until CPU and memory exhaust. No patch confirmed yet. Update Suricata immediately. https://www.valtersit.com/cve/CVE-2026-57227/ #CVE #infosec #Suricata
CRITICAL vuln in Suricata 8.0.0 – 8.0.6 (CVE-2026-94083): DoH2 type confusion can lead to DoS. Upgrade to 8.0.7+ ASAP 🛡️. Details: https://radar.offseq.com/threat/cve-2026-94083-cwe-843-access-of-resource-using-incompatible-type-type-confusion-in-oisf-suricata-a9f0752b258da862 #OffSeq #Suricata #...
Suricata <8.0.7 has a CRITICAL use-after-free flaw (CVE-2026-94084, CVSS 9.4). Affected by certain HTTP/2 rules. Upgrade to 8.0.7+ to mitigate risks. https://radar.offseq.com/threat/cve-2026-94084-cwe-416-use-after-free-in-oisf-suricata-f54e858a25f14d6f #OffSeq #Suricata #Vulnerability
CVE-2026-94084 - suricata
The Suricata network sensor (versions before 8.0.7) can run into a memory error when it checks HTTP/2 traffic that matches certain response‑header rules. This error could cause the…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-94083 - suricata
The Suricata network monitoring tool can stop working if it processes a DNS‑over‑HTTPS request that tries to switch from HTTP 1 to HTTP 2. This happens because the program frees…
Too many irrelevant or confusing CVEs? Use stackflag.com
If you're running Suricata, you already have the data. The question is whether it's usable. Graylog's Suricata IDS/IPS Content Pack parses EVE JSON, normalizes it to GIM, and gives you a ready to use dashboard for alerts and more.
graylog.org/post/suricat...
#Graylog #Suricata #SIEM #NetworkSecurity
This walk through covers configuring Suricata in IDS mode on the Debian firewall. #CybersecurityLab #Suricata #IDS #IPS
Building a cybersecurity virtual lab 4/7: Configuring Suricata on the Debian IDS/IPS
drive.proton.me/urls/NH9SG0Z...
We're pleased to announce the release of #Suricata 8.0.7! 🎉
This is another release with a higher-than-usual number of security fixes, due to AI-assisted analysis. Please update!
Get the release: 🔸 8.0.7: www.openinfosecfoundation.org/download/sur...
Read more: forum.suricata.io/t/suricata-8...
CVE-2026-45764 - suricata
If you run Suricata versions older than 7.0.16 or 8.0.5, specially crafted web traffic can make the program crash, causing it to stop monitoring your network. Update to the newer…
Too many irrelevant or confusing CVEs? Use stackflag.com
Welcome Profitap to the #Suricata Community and to SuriCon! They’re joining us as Community Partner sponsors and we’re so grateful for their support.
Profitap delivers packet-based network intelligence to strengthen network performance. Learn more about them: www.profitap.com