Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Shane Dugan

Researcher fromCorelight
#21022of 57,652
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-95652
7.5
2026-07-21
Suricata · Suricata · CVE-2026-63446
**Name of the Vulnerable Software and Affected Versions** Suricata versions 8.0.0 through 8.0.5 **Description** The `AppLayerParserSetTransactionInspectId()` function in `src/app-layer-parser.c` uses an inverted guard, which results in only already-inspected transactions being marked as inspected. When flows are processed via a pass rule or pass-the-flow exception policy, detection is skipped, leaving completed transactions unmarked. Consequently, these transactions are never freed and are repeatedly rescanned. This causes the per-flow list to grow without bound with quadratic cleanup cost, leading to CPU and memory exhaustion. **Recommendations** Update to version 8.0.6.
PT-2026-61509
6.5
2026-07-18
Suricata · Suricata · CVE-2026-57224
**Name of the Vulnerable Software and Affected Versions** Suricata versions prior to 8.0.6 **Description** An issue was identified in Suricata that requires a security update. **Recommendations** Update to version 8.0.6.