CVE-2026-45763

Source
https://cve.org/CVERecord?id=CVE-2026-45763
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45763.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45763
Aliases
  • GHSA-9h43-frr8-xx6m
Downstream
Related
Published
2026-09-10T13:24:43Z
Modified
2026-09-12T03:46:21Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Suricata lua: sandbox allocation limit not enforced for new allocations
Details

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory limit was not consistently enforced for new allocations. Certain Lua allocation patterns could exceed security.lua.max-bytes without triggering the intended memory limit, making the configured sandbox limit unreliable. This requires Lua rules to be enabled and an affected Lua script/rule to be loaded. Version 8.0.5 contains a fix. As a workaround, disable security.lua.allow-rules unless Lua rules are required.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-770"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45763.json"
}
References

Affected packages

Git / github.com/oisf/suricata

Affected ranges

Type
GIT
Repo
https://github.com/oisf/suricata
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.0.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

suricata-8.*
suricata-8.0.0
suricata-8.0.1
suricata-8.0.2
suricata-8.0.3
suricata-8.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45763.json"