PT-2026-4990 · Open Information Security Foundation · Suricata

Victorjulien

·

Published

2026-01-01

·

Updated

2026-01-27

·

CVE-2026-22261

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 8.0.3 Suricata versions prior to 7.0.14
Description Suricata is a network IDS, IPS and NSM engine. Inefficiencies in extended forwarding format (xff) handling, particularly for alerts that are not triggered within a transaction (tx), can cause significant performance degradation. Disabling XFF support in the eve configuration can serve as a workaround. The setting is disabled by default.
Recommendations Update to Suricata version 8.0.3 or later. Update to Suricata version 7.0.14 or later. Disable XFF support in the eve configuration as a temporary workaround.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-00963
CVE-2026-22261
GHSA-5JVG-5J3P-34CF
OPENSUSE-SU-2026:10082-1

Affected Products

Suricata