Allocation of Resources Without Limits or Throttling in Suricata - CVE-2026-31935
Published: April 27, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the http2 parser when processing crafted HTTP/2 continuation frames. A remote attacker can send a flood of crafted continuation frames to cause a denial of service.
The issue can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system.