Allocation of Resources Without Limits or Throttling in Suricata - CVE-2026-57227
Published: July 22, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the MQTT parser when processing repeated PUBREC or PUBREL messages within a transaction. A remote attacker can send specially crafted MQTT traffic to cause a denial of service.
The issue can lead to excessive resource consumption and slowdown before service disruption occurs.