Back to CVE List

CVE-2026-31935

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-400
Source
NVD
Vendor
OISF
Product
suricata

External References

Discussion (0)

Add Comment

No comments yet. Be the first!