Official source evidencegithub.comVersioned article
Official source article · github.com

Release 8.0.6 · OISF/suricata · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs16

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-71855Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state
  • CVE-2026-57229Suricata smtp/mime: incomplete state reset allows detection bypass
  • CVE-2026-63450Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection
  • CVE-2026-57223Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation
  • CVE-2026-63448Suricata smb: some SMB flows can cause resource exhaustion
  • CVE-2026-57227Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages
  • CVE-2026-57226Suricata swf: heap buffer overflow in SWF decompression depth handling
  • CVE-2026-63449Suricata sip: large SIP message bodies can evade detection with frame keyword
  • CVE-2026-71418Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption
  • CVE-2026-63447Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
  • CVE-2026-57225Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading
  • CVE-2026-63452Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption
  • CVE-2026-57222Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6
  • CVE-2026-63451Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load
  • CVE-2026-63446Suricata app-layer: passed flows can retain transactions, causing resource exhaustion
  • CVE-2026-57224Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion

Source and provenance

Original title: Release 8.0.6 · OISF/suricata · GitHub. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗