Flow State Reuse Vulnerability in Suricata Network Security Engine
CVE-2026-71855

5.9MEDIUM

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-71855?

In Suricata, prior to versions 7.0.17 and 8.0.6, a vulnerability exists where an IPv4 and IPv6 flow can be incorrectly treated as equal. This occurs due to the lack of comparison between IP families when flow attributes align, allowing an IPv6 packet to erroneously adopt an IPv4 flow state, and vice versa. This misconfiguration can lead to detection bypass or incorrect flowbit state, compromising network monitoring and security functions. It is crucial for users to upgrade to the fixed versions to mitigate these risks.

Affected Version(s)

suricata >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6

suricata < 7.0.17 < 7.0.17

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.