CVE-2026-45766: CWE-400: Uncontrolled Resource Consumption in OISF suricata
CVE-2026-45766 is a high-severity vulnerability in Suricata, a network intrusion detection and prevention system. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded, allowing crafted NFS traffic to cause excessive memory consumption. This can lead to a denial of service condition. Fixed in Suricata versions 7.0.16 and 8.0.5. Disabling NFS application-layer parsing is a recommended workaround if that functionality is not required.
AI Analysis
Technical Summary
Suricata versions before 7.0.16 and 8.0.5 contain a vulnerability (CVE-2026-45766) due to insufficient bounding of certain NFS parser state structures. This flaw allows crafted NFS traffic to trigger uncontrolled resource consumption, specifically excessive memory use, potentially causing a denial of service. The issue is addressed in versions 7.0.16 and 8.0.5 by applying proper bounds checks. Users not requiring NFS parsing can mitigate the risk by disabling this feature.
Potential Impact
Exploitation of this vulnerability can result in Suricata consuming excessive memory, leading to denial of service. There is no impact on confidentiality or integrity reported. No known exploits are currently observed in the wild.
Mitigation Recommendations
Upgrade Suricata to version 7.0.16 or later, or 8.0.5 or later, where the vulnerability is fixed. As a temporary workaround, disable NFS application-layer parsing if it is not needed. No other mitigation steps are indicated by the vendor advisory.
CVE-2026-45766: CWE-400: Uncontrolled Resource Consumption in OISF suricata
Description
CVE-2026-45766 is a high-severity vulnerability in Suricata, a network intrusion detection and prevention system. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded, allowing crafted NFS traffic to cause excessive memory consumption. This can lead to a denial of service condition. Fixed in Suricata versions 7.0.16 and 8.0.5. Disabling NFS application-layer parsing is a recommended workaround if that functionality is not required.
CVSS v3.1
Score 7.5high
Affected software
OISF
suricata
pkg:github/oisf/suricataRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Suricata versions before 7.0.16 and 8.0.5 contain a vulnerability (CVE-2026-45766) due to insufficient bounding of certain NFS parser state structures. This flaw allows crafted NFS traffic to trigger uncontrolled resource consumption, specifically excessive memory use, potentially causing a denial of service. The issue is addressed in versions 7.0.16 and 8.0.5 by applying proper bounds checks. Users not requiring NFS parsing can mitigate the risk by disabling this feature.
Potential Impact
Exploitation of this vulnerability can result in Suricata consuming excessive memory, leading to denial of service. There is no impact on confidentiality or integrity reported. No known exploits are currently observed in the wild.
Mitigation Recommendations
Upgrade Suricata to version 7.0.16 or later, or 8.0.5 or later, where the vulnerability is fixed. As a temporary workaround, disable NFS application-layer parsing if it is not needed. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-13T07:45:21.250Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa32b5891cc7f3848d53ffe
Added to database: 09/10/2026, 22:12:40 UTC
Last enriched: 09/10/2026, 22:17:57 UTC
Last updated: 09/11/2026, 03:05:14 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.