CVE-2026-31935
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.
- Affected products
- Suricata, Libsuricata8 0 4
- Oisf Suricata
- < 7.0.15, 8.0.4
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-770, CWE-400
- NVD status
- Analyzed
- Published
- 2026-04-02
CVE-2026-31935 at NVD
No indexed exploits for CVE-2026-31935 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-31935 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.