
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-57227 is a denial-of-service vulnerability in OISF Suricata's MQTT parser caused by unbounded resource consumption from repeated PUBREC and PUBREL messages. It affects Suricata versions 7.x prior to 7.0.17 and 8.x prior to 8.0.6. The vulnerability was published on July 21, 2026, with patches released in Suricata 7.0.17 and 8.0.6. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is improper resource management in Suricata's MQTT application-layer parser, classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Allocation of Resources Without Limits or Throttling). The parser appends repeated MQTT PUBREC or PUBREL messages to a transaction without enforcing any upper bound on the number of such messages, allowing an attacker to craft malicious MQTT traffic that causes excessive memory or CPU consumption. Exploitation requires no authentication, no user interaction, and is achievable remotely over the network, making it particularly dangerous in remote IDS/IPS deployment scenarios (GitHub Advisory). Patches are available in commits for both the 7.0.17 and 8.0.6 release branches (Suricata 7.0.17 Commit, Suricata 8.0.6 Commit).
Successful exploitation causes Suricata to enter an infinite loop or crash, resulting in a complete loss of availability for the IDS/IPS sensor. Because Suricata is a network security monitoring tool, its disruption can blind defenders to ongoing attacks, effectively neutralizing network-level threat detection. There is no impact on confidentiality or integrity — the sole consequence is availability loss (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of writing. The vulnerability is unauthenticated and remotely exploitable with low attack complexity, meaning any attacker capable of sending crafted MQTT traffic to a monitored network segment can trigger it. The CVE status was listed as "Reserved" at the time of Feedly ingestion, and no CISA KEV listing or threat actor attribution has been identified (GitHub Advisory, Feedly).
journalctl -u suricata).Upgrade Suricata to version 7.0.17 or 8.0.6, which enforce bounds on PUBREC/PUBREL message appending in the MQTT parser (GitHub Advisory). As a temporary workaround for environments where MQTT inspection is not required, disable the MQTT app-layer parser by setting app-layer.protocols.mqtt.enabled: no in the Suricata configuration file. Organizations should prioritize patching given the zero-privilege, network-accessible nature of the vulnerability (Suricata Release).
The Suricata project announced the releases of 7.0.17 and 8.0.6 via their official forum and blog, explicitly referencing this and related security fixes (Suricata Forum, Suricata Blog). OpenSUSE and SUSE issued security announcements for updated Suricata packages addressing this CVE (OpenSUSE Security). Tenable published Nessus detection plugins (IDs 330413 and 344723) to identify vulnerable Suricata installations (Tenable).
Verfügbarkeit von Korrekturen in den wichtigsten Linux-Distributionen und deren Versionen.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"