7.5

CVE-2026-57227

Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or denial of service. This issue is fixed in versions 8.0.6 and 7.0.17.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version >= 7.0.0 < 7.0.17
Oisf ≫ Suricata Version >= 8.0.0 < 8.0.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.337
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://github.com/OISF/suricata/releases/tag/suricata-7.0.17
Release Notes
https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
Release Notes
https://github.com/OISF/suricata/security/advisories/GHSA-7h2h-hpj2-9w6p
Vendor Advisory
Mitigation
https://github.com/OISF/suricata/commit/03ba8a71d827dd36a0ceb512f45d2f440f260a3a
Patch
https://github.com/OISF/suricata/commit/5cde93dea38533c9b225128ba9d54955997dc273
Patch
https://github.com/OISF/suricata/commit/c03666d261256df5a2d1f5800872da8a5addf6a5
Patch
https://redmine.openinfosecfoundation.org/issues/8525
Permissions Required