CVE-2026-31933 identifies a denial-of-service vulnerability in Suricata, a network IDS/IPS/NSM engine, affecting versions prior to 7.0.15 and 8.0.4. An unauthenticated attacker can exploit this with low complexity by sending specially crafted network traffic, leading to significant performance degradation and potential service disruption in IDS mode. This issue carries a CVSS score of 7.5 (High) due to its high impact on availability. There is currently no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog. Community discussion and media coverage remain minimal, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.0.15CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.4CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.