Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
CVE-2026-63448
This medium-severity CVE scores 5.9 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit-prediction score not yet available (the EPSS model rescores nightly; freshly-published CVEs typically appear within 48 hours). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 5.9
- EG Score
- 5.9(low)
- EG Risk
- 31(Track)EG Risk 31/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity59% × 45%Exploitation0% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
September 18, 2026
Last Modified
September 18, 2026
Advisory Details (10)
Auto-updated Sep 18, 20268.0.6
Patch available: OISF/suricata suricata-8.0.6
https://github.com/OISF/suricata/releases/tag/suricata-8.0.67.0.17
Patch available: OISF/suricata suricata-7.0.17
https://github.com/OISF/suricata/releases/tag/suricata-7.0.17commit c8f68b0e4f9e (OISF/suricata)
Fix landed in OISF/suricata commit c8f68b0e4f9e — awaiting tagged release
https://github.com/OISF/suricata/commit/c8f68b0e4f9e721dca1c9ed6e08597c6964c7ac3commit bc39274a638d (OISF/suricata)
Patch available: OISF/suricata suricata-7.0.17 (contains commit bc39274a638d)
https://github.com/OISF/suricata/commit/bc39274a638d1cca2391cfa4891c8b6c255ff9cecommit 9a54a043516e (OISF/suricata)
Patch available: OISF/suricata suricata-8.0.6 (contains commit 9a54a043516e)
https://github.com/OISF/suricata/commit/9a54a043516e644bb7b9d34117a91977f950a281commit 88adab8bd3d6 (OISF/suricata)
Patch available: OISF/suricata suricata-7.0.17 (contains commit 88adab8bd3d6)
https://github.com/OISF/suricata/commit/88adab8bd3d62912941647ab65032d5ec75c893acommit 7ec9d72d28b9 (OISF/suricata)
Fix landed in OISF/suricata commit 7ec9d72d28b9 — awaiting tagged release
https://github.com/OISF/suricata/commit/7ec9d72d28b9370712cf77a5b9d40d6b5db27cb4commit 755d6c3061de (OISF/suricata)
Patch available: OISF/suricata suricata-8.0.6 (contains commit 755d6c3061de)
https://github.com/OISF/suricata/commit/755d6c3061de4d7ba97f0ed31cdc17ab8cab4476smb: some SMB flows can cause resource exhaustion · Advisory · OISF/suricata · GitHub
https://github.com/OISF/suricata/security/advisories/GHSA-hvvj-c8xx-9g35Weakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 3× in last 7d / 3× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-18 21:17 UTCEG score recompute
- 2026-09-18 20:25 UTCEG score recompute
- 2026-09-18 20:24 UTCMITRE cvelistV5first tracked
Frequently asked(4)
What is CVE-2026-63448?
When was CVE-2026-63448 disclosed?
What is the CVSS score of CVE-2026-63448?
How do I remediate CVE-2026-63448?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-63448
Is Your Infrastructure Affected by CVE-2026-63448?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.