CVE-2026-22259
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).
- Affected products
- Suricata
- Oisf Suricata
- < 7.0.14, 8.0.3
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.5% (41th percentile)
- Weakness
- CWE-400, CWE-770
- NVD status
- Analyzed
- Published
- 2026-01-27
CVE-2026-22259 at NVD
No indexed exploits for CVE-2026-22259 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-22259 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.