Vulnerability Description
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oisf | Suricata | < 7.0.15 |
Related Weaknesses (CWE)
References
- https://github.com/OISF/suricata/security/advisories/GHSA-vxrp-5pg7-7v4xVendor Advisory
- https://redmine.openinfosecfoundation.org/issues/8289Issue TrackingPermissions Required
FAQ
What is CVE-2026-31935?
CVE-2026-31935 is a vulnerability with a CVSS score of 7.5 (HIGH). Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process ...
How severe is CVE-2026-31935?
CVE-2026-31935 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-31935?
Check the references section above for vendor advisories and patch information. Affected products include: Oisf Suricata.