Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS application-layer parsing if it is not needed.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Suricata is a network IDS/IPS that parses Network File System traffic. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. The flaw is captured by CWE-400 and CWE-770.

Affected Systems

The issue affects the open‑source Suricata engine maintained by the Open Information Security Foundation. All builds prior to Suricata 7.0.16 and 8.0.5 are vulnerable. Those versions parse NFS traffic until an update is applied.

Risk and Exploitability

The CVSS base score of 7.5 indicates that exploitation probability is uncertain because no EPSS score is available; it is also not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending malformed NFS packets over the wire, an inference drawn from the description that Suricata parses NFS traffic until a fix is applied, which implies that such traffic can trigger the memory exhaustion. The resultant denial of service can demonstrate a clear and critical availability impact.

Generated by OpenCVE AI on September 11, 2026 at 04:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 7.0.16 or later 8.0.5 where the NFS parser issue has been fixed.
  • If upgrading is not immediately possible disable NFS application‑layer parsing via Suricata configuration to prevent the vulnerable code path.
  • limiting for NFS traffic to reduce the potential impact until a patch or configuration change is in place.

Generated by OpenCVE AI on September 11, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS application-layer parsing if it is not needed.
Title Suricata nfs: unbounded stateful structures can lead to resource exhaustion
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-11T14:43:40.252Z

Reserved: 2026-05-13T07:45:21.250Z

Link: CVE-2026-45766

cve-icon Vulnrichment

Updated: 2026-09-11T14:43:35.552Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:16:56.540

Modified: 2026-09-16T20:18:22.197

Link: CVE-2026-45766

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T21:26:39Z

Links: CVE-2026-45766 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:45:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling