VYPR
High severity7.5NVD Advisory· Published Sep 10, 2026

CVE-2026-45768

CVE-2026-45768

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of responses. Because LDAP can be processed over UDP, crafted traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Version 8.0.5 contains a fix. As a workaround, disable LDAP application-layer parsing where it is not required. Alternatively, use a rule like alert ldap any any -> any any (sid: 1; ldap.responses.count: >1024; bypass;).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Oisf/Suricatainferred2 versions
    >=8.0.0,<8.0.5+ 1 more
    • (no CPE)range: >=8.0.0,<8.0.5
    • (no CPE)range: 8.0.0 <= version < 8.0.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.