CVE-2026-31933

Name
CVE-2026-31933
Description
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/OISF/suricata/security/advisories/GHSA-hvp5-gpr6-j4gp
security-advisories@github.com https://redmine.openinfosecfoundation.org/issues/8272

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= None < 7.0.15
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= 8.0.0 < 8.0.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
suricata edge-community 8.0.3-r0 Steve McMaster <steve@mcmaster.io> possibly vulnerable
suricata edge-community 8.0.2-r0 Steve McMaster <steve@mcmaster.io> possibly vulnerable
suricata edge-community 8.0.0-r0 Steve McMaster <steve@mcmaster.io> possibly vulnerable
suricata edge-community 7.0.10-r1 Steve McMaster <steve@mcmaster.io> possibly vulnerable
suricata edge-community 7.0.10-r0 Steve McMaster <steve@mcmaster.io> possibly vulnerable
suricata edge-community 7.0.8-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata edge-community 7.0.7-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata edge-community 7.0.6-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata edge-community 6.0.4-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata edge-community 6.0.3-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata 3.23-community 8.0.0-r0 Steve McMaster <steve@mcmaster.io> possibly vulnerable