CVE-2026-31935: Suricata http2: unbounded resource consumption
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31935?
CVE-2026-31935 has a high severity due to its potential for unbounded resource consumption leading to service disruption.
How do I fix CVE-2026-31935?
To fix CVE-2026-31935, upgrade Suricata to version 7.0.15 or later, or 8.0.4 or later.
What types of systems are affected by CVE-2026-31935?
CVE-2026-31935 affects Suricata versions prior to 7.0.15 and between 8.0.0 and 8.0.4.
What is the impact of exploiting CVE-2026-31935?
Exploiting CVE-2026-31935 can lead to memory exhaustion and result in the Suricata process being shut down.
How can I detect CVE-2026-31935 vulnerabilities in my system?
You can detect CVE-2026-31935 vulnerabilities by reviewing your Suricata version and looking for evidence of HTTP2 continuation frame flooding.