NULL pointer dereference in Suricata - CVE-2026-45747
Published: June 3, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in TlsGetCertInfo when processing crafted TLS traffic with absent certificate fields. A remote attacker can send crafted TLS traffic to cause a denial of service.
Only deployments using affected Lua TLS scripting are vulnerable.