CVE-2023-35853: Oisf Suricata

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.

Affected products

  • Oisf Suricata: before 6.0.13 (fixed in 6.0.13)

Published 2023-06-19. Last modified 2026-06-17.