Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or denial of service. This issue is fixed in versions 8.0.6 and 7.0.17.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unbounded resource consumption leading to denial of service
Action: Immediate Patch
AI Analysis

Impact

Suricata's MQTT parser allows an attacker to send repeated PUBREC or PUBREL messages that are appended to a transaction without any limit. This behavior can cause the processor to allocate increasingly large amounts of memory and CPU time for each transaction. The impact is a significant degradation of performance and eventual denial of service when the system runs out of resources. The vulnerability stems from improper resource limits (CWE-400) and improper handling of growing data structures (CWE-770).

Affected Systems

The issue affects any installation of OISF Suricata from version 7.0.0 through 7.0.16 and from 8.0.0 through 8.0.5. Versions 7.0.17 and 8.0.6 include the fix and are not susceptible.

Risk and Exploitability

With a CVSS score of 7.5, this vulnerability is categorized as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker forging MQTT control messages to a network component where Suricata is operating, allowing remote or local exploitation depending on exposure. Successful exploitation would cause the Suricata engine to consume excessive CPU and memory, slowing or stopping packet inspection and potentially leading to a broader denial of service for monitored traffic.

Generated by OpenCVE AI on September 19, 2026 at 10:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 7.0.17 or 8.0.6 to apply the official fix.
  • If upgrade is not immediately possible, configure network firewalls or access controls to block or heavily rate‑limit incoming MQTT control traffic such as PUBREC and PUBREL messages reaching the Suricata host.
  • Restart the Suricata service after applying the patch or configuration changes to ensure the updated code and settings take effect.

Generated by OpenCVE AI on September 19, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or denial of service. This issue is fixed in versions 8.0.6 and 7.0.17.
Title Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:47:38.925Z

Reserved: 2026-06-24T02:21:33.811Z

Link: CVE-2026-57227

cve-icon Vulnrichment

Updated: 2026-09-22T15:47:34.739Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:01.217

Modified: 2026-09-29T12:48:01.487

Link: CVE-2026-57227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling