NULL pointer dereference in Suricata - CVE-2026-57225
Published: July 22, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in JSON/NDJSON dataset loading when loading dataset enrichment files with a configured value_key that contains a non-string JSON value. A local user can supply a specially crafted JSON or NDJSON dataset file to cause a denial of service.
The issue can be triggered during startup, configuration test mode, or rule reload, before traffic processing.