CVE-2026-31937 identifies a performance degradation vulnerability in Suricata, a network IDS, IPS, and NSM engine, affecting versions prior to 7.0.15 due to an inefficiency in DCERPC buffering. This issue carries a CVSS score of 7.5 (High), indicating it is remotely exploitable with low attack complexity and no user interaction required, primarily impacting system availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in common repositories like Metasploit or ExploitDB. Community discussion and media coverage for this vulnerability remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.0.15CPE matchmatch criteria | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.