CVE-2026-31931 is a high-severity NULL dereference vulnerability affecting Suricata versions 8.0.0 through 8.0.3, where the use of the "tls.alpn" rule keyword can cause the network IDS/IPS engine to crash. Rated 7.5 HIGH, this vulnerability can be exploited remotely over the network with low attack complexity and no user interaction, leading to a denial of service for the affected Suricata instance. There is currently no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB. It is not listed in CISA's KEV catalog, and community discussion is minimal. Organizations using affected Suricata versions should upgrade to 8.0.4 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.0.4CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.