Vendor
OISF vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in OISF: 2 in the last 7 days and 30 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94084, was published on 20 September 2026. 1 technology has a page of its own.
- Last 7 days
- 2
- Last 90 days
- 30
- Critical, all time
- 3
- Exploited in the wild
- 0
About OISF
The Open Information Security Foundation (OISF) is a non-profit organization dedicated to building and maintaining open-source security technologies.
OISF technologies
Latest OISF vulnerabilities
- CVE-2026-94084: Suricata use-after-free in HTTP/2 response header detectioncriticalCVSS 9.4EPSS 0.5%
- CVE-2026-94083: Suricata DoH2 type confusion in HTTP state cleanupcriticalCVSS 9.4EPSS 0.5%
- CVE-2026-71855: Suricata IP family validation bypass in flow comparisonmediumCVSS 5.9EPSS 0.5%
- CVE-2026-71418: Suricata DNS-over-HTTP/2 buffer memory handling denial of servicehighCVSS 7.5EPSS 0.6%
- CVE-2026-63452: Suricata HTTP/1 compression bomb denial of servicehighCVSS 7.5EPSS 0.6%
- CVE-2026-63448: Suricata SMB parser unbounded transaction accumulation DoSmediumCVSS 5.9EPSS 0.7%
- CVE-2026-63447: Suricata FTP parser denial of service via transaction limit bypasshighCVSS 7.5EPSS 0.6%
- CVE-2026-63446: Suricata inverted flag logic in transaction cleanuphighCVSS 7.5EPSS 0.7%
- CVE-2026-57229: Suricata SMTP MIME parser state reset flawmediumCVSS 5.3EPSS 0.4%
- CVE-2026-57228: Suricata out-of-bounds read in MIME quoted-printable decoderhighCVSS 8.2EPSS 0.6%
- CVE-2026-57227: Suricata MQTT parser resource exhaustion in transaction handlinghighCVSS 7.5EPSS 0.7%
- CVE-2026-57223: Suricata unquoted service path privilege escalation on WindowshighCVSS 7EPSS 0.1%
- CVE-2026-57224: Suricata DHCP and RDP parser transaction leak causing DoSmediumCVSS 6.5EPSS 0.4%
- CVE-2026-57222: Suricata IPv4/IPv6 address hash collision in IP pair trackingmediumCVSS 5.3EPSS 0.4%
- CVE-2026-45770: Suricata Lua sandbox bypass via excessive flow variableshighCVSS 7.5EPSS 0.5%
- CVE-2026-45769: Suricata IKEv2 parser unbounded memory consumptionhighCVSS 7.5EPSS 1.8%
- CVE-2026-45768: Suricata unbounded LDAP response buffering denial of servicehighCVSS 7.5EPSS 0.7%
- CVE-2026-45767: Suricata path traversal in rule load/save commandmediumCVSS 4.4EPSS 0.4%
- CVE-2026-45766: Suricata NFS parser unbounded state memory exhaustionhighCVSS 7.5EPSS 0.6%
- CVE-2026-45765: Suricata DNP3 unbounded reassembly denial of servicehighCVSS 7.5EPSS 0.6%
- CVE-2026-45764: Suricata HTTP/2 type confusion denial of servicecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-45762: Suricata IP defragmentation denial of servicehighCVSS 7.5EPSS 0.6%
- CVE-2026-45761: Suricata heap buffer overflow in rule parsinglowCVSS 3.3EPSS 0.2%
- CVE-2026-45759: Suricata HTTP Content-Disposition denial of servicehighCVSS 7.5EPSS 0.8%
- CVE-2026-45752: Suricata use-after-free in decompress transformsmediumCVSS 5.9EPSS 0.5%
Most severe OISF vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-94084: Suricata use-after-free in HTTP/2 response header detectioncriticalCVSS 9.4EPSS 0.5%
- CVE-2026-94083: Suricata DoH2 type confusion in HTTP state cleanupcriticalCVSS 9.4EPSS 0.5%
- CVE-2026-45764: Suricata HTTP/2 type confusion denial of servicecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-57228: Suricata out-of-bounds read in MIME quoted-printable decoderhighCVSS 8.2EPSS 0.6%
- CVE-2026-45769: Suricata IKEv2 parser unbounded memory consumptionhighCVSS 7.5EPSS 1.8%
- CVE-2026-45759: Suricata HTTP Content-Disposition denial of servicehighCVSS 7.5EPSS 0.8%
- CVE-2026-46387: Suricata HTTP/2 decompression denial of servicehighCVSS 7.5EPSS 0.7%
- CVE-2026-57227: Suricata MQTT parser resource exhaustion in transaction handlinghighCVSS 7.5EPSS 0.7%
- CVE-2026-45768: Suricata unbounded LDAP response buffering denial of servicehighCVSS 7.5EPSS 0.7%
- CVE-2026-63446: Suricata inverted flag logic in transaction cleanuphighCVSS 7.5EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 15 | 1 | |
| 14 Sep 2026 | 14 | 2 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/oisf.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OISF vulnerabilities", https://junglewise.ai/threats/vendors/oisf, 26 September 2026.