Allocation of Resources Without Limits or Throttling in Suricata - CVE-2026-45763
Published: June 3, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the Lua sandbox when executing Lua rules. A remote attacker can use a crafted Lua script or rule with certain allocation patterns to cause a denial of service.
This requires Lua rule execution to be enabled and an affected Lua script or rule to be loaded.