CVE-2026-45747: Oisf Suricata

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.

Affected products

  • Oisf Suricata: before 7.0.16 (fixed in 7.0.16)

Published 2026-09-10. Last modified 2026-09-28.