VYPR
High severity7.5NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026

CVE-2026-45747

CVE-2026-45747

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (TlsGetCertInfo function), or update scripts to handle missing certificate fields where possible.

Affected products

2
  • Oisf/Suricatainferred2 versions
    <7.0.16+ 1 more
    • (no CPE)range: <7.0.16
    • (no CPE)range: <7.0.16

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.