CVE-2026-31931

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

07 Apr 2026, 18:28

Type Values Removed Values Added
References () https://github.com/OISF/suricata/security/advisories/GHSA-gr22-4784-xvw3 - () https://github.com/OISF/suricata/security/advisories/GHSA-gr22-4784-xvw3 - Vendor Advisory
References () https://redmine.openinfosecfoundation.org/issues/8294 - () https://redmine.openinfosecfoundation.org/issues/8294 - Issue Tracking, Permissions Required
First Time Oisf
Oisf suricata
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

02 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 14:16

Updated : 2026-04-07 18:28


NVD link : CVE-2026-31931

Mitre link : CVE-2026-31931

CVE.ORG link : CVE-2026-31931


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-476

NULL Pointer Dereference