CVE-2026-31935

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

07 Apr 2026, 21:20

Type Values Removed Values Added
First Time Oisf
Oisf suricata
References () https://github.com/OISF/suricata/security/advisories/GHSA-vxrp-5pg7-7v4x - () https://github.com/OISF/suricata/security/advisories/GHSA-vxrp-5pg7-7v4x - Vendor Advisory
References () https://redmine.openinfosecfoundation.org/issues/8289 - () https://redmine.openinfosecfoundation.org/issues/8289 - Issue Tracking, Permissions Required
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

02 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 15:16

Updated : 2026-04-07 21:20


NVD link : CVE-2026-31935

Mitre link : CVE-2026-31935

CVE.ORG link : CVE-2026-31935


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling