LOW 3.3 NVD
CVE-2026-57225
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-conte
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6.
References
- https://github.com/OISF/suricata/commit/3ca2ed25a324597a85a2ab11595c3b0689468ea5
- https://github.com/OISF/suricata/commit/bd3293aca714f5d090b73e7d9be0e5cd7e3f5f53
- https://github.com/OISF/suricata/pull/15699
- https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
- https://github.com/OISF/suricata/security/advisories/GHSA-vqqx-88xw-qqvc
This low severity vulnerability with a CVSS score of 3.3 was published on 2026-09-18 via NVD.
vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.