
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31931 is a NULL pointer dereference vulnerability in Suricata, the open-source network IDS, IPS, and NSM engine. When the tls.alpn rule keyword is used in detection rules, Suricata can crash due to improper handling of a NULL pointer, resulting in a denial of service. The vulnerability affects Suricata versions 8.0.0 through 8.0.3 and was patched in version 8.0.4, released on March 17, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is a NULL pointer dereference (CWE-476) in Suricata's handling of the tls.alpn rule keyword, which is used to match the TLS Application-Layer Protocol Negotiation extension in network traffic. When a rule using this keyword is evaluated against certain network traffic, Suricata dereferences a pointer that is unexpectedly NULL, causing an application crash. The vulnerability is remotely exploitable with no authentication, privileges, or user interaction required — an attacker simply needs to send crafted or opportunistic network traffic that triggers evaluation of a tls.alpn-based rule. The issue was discovered by OSS-Fuzz (GitHub Advisory).
Successful exploitation causes Suricata to crash, resulting in a complete loss of availability for the IDS/IPS/NSM monitoring function. This means network traffic is no longer inspected or blocked during the outage, potentially leaving the protected network exposed to other threats. There is no impact on confidentiality or data integrity, as the vulnerability only affects availability (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.046%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that the target Suricata instance has at least one active rule using the tls.alpn keyword; notably, no common rulesets are known to use this keyword by default (GitHub Advisory).
tls.alpn keyword active.tls.alpn rule against the packet, dereferences a NULL pointer, and crashes — disabling IDS/IPS/NSM monitoring for the duration of the outage (GitHub Advisory).syslog, journald) showing unexpected Suricata process termination.Upgrade Suricata to version 8.0.4 or later, which contains the official patch for this vulnerability (GitHub Advisory, Suricata Release). As a temporary workaround for organizations unable to upgrade immediately, disable or remove any IDS/IPS rules that use the tls.alpn keyword. The advisory notes that no common rulesets (e.g., Emerging Threats, Suricata default rules) use this keyword, so the workaround impact should be minimal for most deployments (GitHub Advisory).
The vulnerability was discovered by OSS-Fuzz, Google's continuous fuzzing service for open-source software, and responsibly disclosed to the OISF team. The Suricata project published the advisory and patched release promptly. Coverage appeared on security aggregators and community forums, including the Suricata community forum and openSUSE security announcements, but no significant controversy or widespread concern was noted given the limited real-world rule usage of the affected keyword (Suricata Forum, openSUSE).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
suricata
devel
suricata
jammy
suricata
jammy (esm-apps)
suricata
noble
suricata
noble (esm-apps)
suricata
resolute
suricata
resolute (esm-apps)
suricata
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."