Junglewise Threat Intelligence

CVE-2026-45763: Suricata Lua sandbox memory limit bypass

CVE-2026-45763 · Severity: medium · CVSS 5.9 · Published 2026-09-10

Technologies: OISF Suricata. Vendors: OISF.

Executive brief

Suricata is a network security monitoring and intrusion detection system used to monitor and protect network traffic. When Lua-based custom rules are enabled, the memory sandbox designed to limit resource consumption can be bypassed through specific allocation patterns, allowing malicious or poorly written scripts to consume excessive memory and cause service denial. This affects systems that have Lua rule execution enabled.

Technical details

A resource exhaustion vulnerability in Suricata's Lua sandbox exists due to inconsistent enforcement of the memory limit configured via security.lua.max-bytes. Certain Lua allocation patterns can bypass the configured limit without triggering the intended constraint, making the sandbox's resource controls unreliable. The vulnerability requires Lua rules to be enabled (security.lua.allow-rules) and an affected Lua script or rule to be loaded on the system. An attacker who can craft or inject a malicious Lua rule can trigger excessive memory allocation, causing a denial of service by exhausting heap memory. The vulnerability affects Suricata 8.0.0 through 8.0.4; version 8.0.5 and later include a fix. Disabling security.lua.allow-rules serves as a workaround if Lua rules are not required.

Affected products

  • OISF Suricata 8.0.0 to 8.0.4

Timeline

  • 2026-06-02: disclosed: GitHub Security Advisory GHSA-9h43-frr8-xx6m published
  • 2026-05-19: patched: Suricata 8.0.5 released with fix

References

Related threats