CVE-2026-71855
5.9 MEDIUMpublic exploit availablePublished 2026-09-18 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-697
Public exploit & PoC references
- https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f
- https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701
- https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20
- https://github.com/OISF/suricata/releases/tag/suricata-7.0.17
- https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
- https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586
All references
- https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f
- https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701
- https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20
- https://github.com/OISF/suricata/releases/tag/suricata-7.0.17
- https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
- https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586
- https://redmine.openinfosecfoundation.org/issues/8558
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-101912PoC
- UNSCOREDCVE-2026-101913PoC
- MEDIUMCVE-2026-57222PoC
- HIGHCVE-2026-61672PoC
- MEDIUMCVE-2026-61795PoC
- MEDIUMCVE-2026-79913PoC
- MEDIUMCVE-2026-85292PoC
- HIGHCVE-2026-92087PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.