{"api_version":"1","generated_at":"2026-09-20T07:50:45+00:00","cve":"CVE-2026-71855","urls":{"html":"https://cve.report/CVE-2026-71855","api":"https://cve.report/api/cve/CVE-2026-71855.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-71855","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-71855"},"summary":{"title":"Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state","description":"Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-09-18 21:18:08","updated_at":"2026-09-18 21:18:08"},"problem_types":["CWE-697","CWE-697 CWE-697: Incorrect Comparison"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701","name":"https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://redmine.openinfosecfoundation.org/issues/8558","name":"https://redmine.openinfosecfoundation.org/issues/8558","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/OISF/suricata/releases/tag/suricata-8.0.6","name":"https://github.com/OISF/suricata/releases/tag/suricata-8.0.6","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586","name":"https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/OISF/suricata/releases/tag/suricata-7.0.17","name":"https://github.com/OISF/suricata/releases/tag/suricata-7.0.17","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f","name":"https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20","name":"https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-71855","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71855","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"OISF","product":"suricata","version":"affected >= 8.0.0, < 8.0.6","platforms":[]},{"source":"CNA","vendor":"OISF","product":"suricata","version":"affected < 7.0.17","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"71855","cve":"CVE-2026-71855","epss":"0.003120000","percentile":"0.242880000","score_date":"2026-09-19","updated_at":"2026-09-20 00:14:29"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"suricata","vendor":"OISF","versions":[{"status":"affected","version":">= 8.0.0, < 8.0.6"},{"status":"affected","version":"< 7.0.17"}]}],"descriptions":[{"lang":"en","value":"Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-697","description":"CWE-697: Incorrect Comparison","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T20:25:58.646Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586"},{"name":"https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f"},{"name":"https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701"},{"name":"https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20"},{"name":"https://github.com/OISF/suricata/releases/tag/suricata-7.0.17","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/releases/tag/suricata-7.0.17"},{"name":"https://github.com/OISF/suricata/releases/tag/suricata-8.0.6","tags":["x_refsource_MISC"],"url":"https://github.com/OISF/suricata/releases/tag/suricata-8.0.6"},{"name":"https://redmine.openinfosecfoundation.org/issues/8558","tags":["x_refsource_MISC"],"url":"https://redmine.openinfosecfoundation.org/issues/8558"}],"source":{"advisory":"GHSA-fvwh-wjcq-2586","discovery":"UNKNOWN"},"title":"Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-71855","datePublished":"2026-09-18T20:25:58.646Z","dateReserved":"2026-08-07T18:26:53.523Z","dateUpdated":"2026-09-18T20:25:58.646Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 21:18:08","lastModifiedDate":"2026-09-18 21:18:08","problem_types":["CWE-697","CWE-697 CWE-697: Incorrect Comparison"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"71855","Ordinal":"1","Title":"Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow sta","CVE":"CVE-2026-71855","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"71855","Ordinal":"1","NoteData":"Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.","Type":"Description","Title":"Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow sta"}]}}}