CVE-2026-31935 is a high-severity denial-of-service vulnerability affecting Suricata, a network IDS/IPS/NSM engine, prior to versions 7.0.15 and 8.0.4. An unauthenticated attacker can exploit this by flooding the system with crafted HTTP/2 continuation frames, leading to memory exhaustion and the Suricata process being shut down. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and requires no user interaction, making it easily exploitable over the network to achieve a complete loss of availability for the Suricata service. There is currently no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.0.15CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.4CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.