Suricata · Suricata · CVE-2026-57225
**Name of the Vulnerable Software and Affected Versions**
Suricata versions 8.0.0 through 8.0.5
**Description**
Suricata is a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine. The file `src/datasets-context-json.c` incorrectly assumes that a configured JSON or NDJSON dataset `value key` always resolves to a string. If a dataset or rule feed contains a non-string value for this key, it can trigger a NULL pointer dereference—a condition where the software attempts to read data from a memory address that is null—during startup, configuration test mode, or rule reload. This results in the application crashing before traffic processing begins.
**Recommendations**
Update to version 8.0.6.