CVE-2026-31932 PUBLISHED

Suricata krb5: quadratic complexity in krb5 buffering

Assigner: GitHub_M
Reserved: 10.03.2026 Published: 02.04.2026 Updated: 02.04.2026

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor OISF
Product suricata
Versions
  • Version < 7.0.15 is affected
  • Version >= 8.0.0, < 8.0.4 is affected

References

Problem Types

  • CWE-407: Inefficient Algorithmic Complexity CWE