Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 parsing if it is not required.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

Suricata is a network intrusion detection and prevention engine that processes HTTP/2 traffic. Prior to version 7.0.16 on the 7.x branch and 8.0.5 on the 8.x branch, a protocol change during HTTP/2 processing could trigger type‑confusion (CWE‑843). An attacker can craft an HTTP/2 frame that causes Suricata to crash, leading to denial of service. The vulnerability is fixed in Suricata 7.0.16 and 8.0.5, and a temporary workaround is to disable HTTP/2 parsing when it is not needed.

Affected Systems

OISF Suricata versions earlier than 7.0.16 and 8.0.5 are vulnerable. The security team released patched builds in those specific versions, and all later releases include the fix.

Risk and Exploitability

The CVSS base score of 9.1 classifies the issue as critical, and while the EPSS score is not available, the vulnerability can be triggered by an external attacker who can inject malicious HTTP/2 traffic into the Suricata instance. Successful exploitation causes Suricata to terminate, creating a denial of service. The risk is not yet reflected in the CISA KEV catalog, indicating no confirmed widespread exploitation at the time of analysis.

Generated by OpenCVE AI on September 11, 2026 at 03:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade0.16 or newer.
  • If an upgrade is not immediately possible, disable HTTP/2 parsing in the Suricata configuration to prevent the exploit from being triggered.
  • If upgrade or reconfiguration is delayed, block HTTP/2 traffic at the network perimeter to stop malicious frames from reaching the Suricata instance.

Generated by OpenCVE AI on September 11, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 parsing if it is not required.
Title Suricata http2: protocol-change type confusion can lead to denial of service
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T21:14:30.072Z

Reserved: 2026-05-13T07:45:21.250Z

Link: CVE-2026-45764

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:16:56.250

Modified: 2026-09-10T22:16:56.250

Link: CVE-2026-45764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T03:15:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')