Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Suricata, from version 8.0.0 through 8.0.6, contains a null pointer dereference in the dataset loader for JSON or NDJSON formats. If a configured dataset contains a non‑string value for the key used as a value_key, the engine dereferences a NULL pointer during startup, a configuration test, or rule reload, resulting in an immediate crash. This effect is a denial of service for the IDS/IPS component, preventing it from processing traffic until it is restarted.

Affected Systems

The affected product is the open source Intrusion Detection System maintained by OISF, Suricata. Versions from 8.0.0 up to and including 8.0.6 are impacted; all later releases contain the fix. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 3.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting it has not been widely exploited in the wild. The likely attack vector is through a malicious or corrupted dataset or rule feed, which could be supplied remotely by an attacker who has read access to the update mechanism, or locally by an insider. Because the flaw manifests as a crash rather than code execution, the risk is limited to denial of service.

Generated by OpenCVE AI on September 19, 2026 at 10:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.6 or later.
  • Ensure all configured datasets and rule feeds use string values for the value_key field; review and validate configuration files.
  • If an upgrade is not yet possible, restrict Suricata from loading untrusted datasets or rule feeds and apply whitelist or static verification before loading.

Generated by OpenCVE AI on September 19, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6.
Title Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T18:20:38.141Z

Reserved: 2026-06-24T02:21:33.811Z

Link: CVE-2026-57225

cve-icon Vulnrichment

Updated: 2026-09-21T18:20:35.335Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:01.070

Modified: 2026-09-28T18:35:19.587

Link: CVE-2026-57225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses