Impact
Suricata is a network intrusion detection and prevention engine that processes HTTP/2 traffic. Prior to version 7.0.16 on the 7.x branch and 8.0.5 on the 8.x branch, a protocol change during HTTP/2 processing could trigger type‑confusion (CWE‑843). An attacker can craft an HTTP/2 frame that causes Suricata to crash, leading to denial of service. The vulnerability is fixed in Suricata 7.0.16 and 8.0.5, and a temporary workaround is to disable HTTP/2 parsing when it is not needed.
Affected Systems
OISF Suricata versions earlier than 7.0.16 and 8.0.5 are vulnerable. The security team released patched builds in those specific versions, and all later releases include the fix.
Risk and Exploitability
The CVSS base score of 9.1 classifies the issue as critical, and while the EPSS score is not available, the vulnerability can be triggered by an external attacker who can inject malicious HTTP/2 traffic into the Suricata instance. Successful exploitation causes Suricata to terminate, creating a denial of service. The risk is not yet reflected in the CISA KEV catalog, indicating no confirmed widespread exploitation at the time of analysis.
OpenCVE Enrichment