CVE-2026-31934: Suricata smtp/mine: quadratic complexity in extracting urls
Published Apr 2, 2026
·Updated
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.
Affected Software
1 affected component
OISF Suricata>=8.0.0<8.0.4
Event History
Apr 2, 2026
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31934?
CVE-2026-31934 has been classified as a performance-related vulnerability due to its quadratic complexity issue.
2
How do I fix CVE-2026-31934?
To fix CVE-2026-31934, upgrade Suricata to version 8.0.4 or later.
3
What software is affected by CVE-2026-31934?
CVE-2026-31934 affects Suricata versions from 8.0.0 to before 8.0.4.
4
What is the impact of CVE-2026-31934 on system performance?
CVE-2026-31934 leads to significant performance degradation when extracting URLs from MIME encoded messages.
5
Is CVE-2026-31934 exploitable remotely?
CVE-2026-31934 could potentially be exploited by sending specially crafted MIME encoded SMTP messages.