Impact
Suricata, a network intrusion detection and prevention engine, parses HTTP/2 traffic. In versions prior to 7.0.16 and 8.0.5, a protocol change during parsing can trigger type‑confusion (CWE‑843). Maliciously crafted HTTP/2 frames may cause Suricata to terminate, resulting in a denial of service for systems relying on the engine for monitoring.
Affected Systems
Suricata releases before 7.0.16 and before 8.0.5 are affected. All releases 7.0.16 and newer or 8.0.5 and newer contain the fix.
Risk and Exploitability
The CVSS base score of 9.1 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An external attacker can inject malicious HTTP/2 traffic into a running Suricata instance, triggering the type‑confusion and causing a crash. No publicly known exploitation activity is reported at this time.
OpenCVE Enrichment