Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompress-depth can use the configured depth when allocating in src/util-file-decompression.c instead of limiting the allocation to the Flash file's actual data requirement. A crafted SWF response can therefore trigger an integer-related heap buffer overflow and crash Suricata; the default disabled feature and default depth are not affected. This issue is fixed in versions 8.0.6 and 7.0.17.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-122",
"CWE-190"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57226.json"
}{
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.6"
},
{
"introduced": "0"
},
{
"fixed": "7.0.17"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57226.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "192864224979539733037586966219519213610",
"length": 2209
},
"id": "CVE-2026-57226-007d15e9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/oisf/suricata/commit/82af0aeb7cec39e206a9ca96c4966425eddeaa74",
"target": {
"file": "src/util-file-decompression.c",
"function": "FileSwfDecompression"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"275405343321062405205794929732698709963",
"144766653225240918387621820185440799630",
"60486805435350465644198612319070306078",
"9874142513738138650622108364020974595"
],
"threshold": 0.9
},
"id": "CVE-2026-57226-28280861",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/oisf/suricata/commit/82af0aeb7cec39e206a9ca96c4966425eddeaa74",
"target": {
"file": "src/util-file-decompression.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "192864224979539733037586966219519213610",
"length": 2209
},
"id": "CVE-2026-57226-3e3ee0d1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/oisf/suricata/commit/d9fae18432501674338e28bd33e35788c95d4a98",
"target": {
"file": "src/util-file-decompression.c",
"function": "FileSwfDecompression"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "192864224979539733037586966219519213610",
"length": 2209
},
"id": "CVE-2026-57226-7f929983",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/oisf/suricata/commit/b63224871b0f8b0b1f7b8c22d05ba8a5c5f69fbb",
"target": {
"file": "src/util-file-decompression.c",
"function": "FileSwfDecompression"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"275405343321062405205794929732698709963",
"144766653225240918387621820185440799630",
"17172955168613639703932889437754995674",
"270170486673652698289258520227495121975"
],
"threshold": 0.9
},
"id": "CVE-2026-57226-8f2d977e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/oisf/suricata/commit/b63224871b0f8b0b1f7b8c22d05ba8a5c5f69fbb",
"target": {
"file": "src/util-file-decompression.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"275405343321062405205794929732698709963",
"144766653225240918387621820185440799630",
"17172955168613639703932889437754995674",
"270170486673652698289258520227495121975"
],
"threshold": 0.9
},
"id": "CVE-2026-57226-d48699b2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/oisf/suricata/commit/d9fae18432501674338e28bd33e35788c95d4a98",
"target": {
"file": "src/util-file-decompression.c"
}
}
]
"2026-09-20T14:24:17Z"