CVE-2026-31934 is a high-severity denial-of-service vulnerability affecting Suricata network IDS/IPS engine versions 8.0.0 through 8.0.3. This flaw stems from a quadratic complexity issue when processing URLs in MIME-encoded SMTP messages, leading to a significant performance impact. With a CVSSv3.1 score of 7.5, it can be exploited remotely with low attack complexity. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, nor is it listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.0.4CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.