Description
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution or Crash
Action: Apply Patch
AI Analysis

Impact

Suricata 8.x contains a type confusion flaw in its DoH2 implementation that can trigger an invalid free when the cleanup code for HTTP/2 is executed while the state is actually HTTP/1. This bug manifests when an attacker sends a DoH2 request that includes an HTTP/1 to HTTP/2 upgrade sequence; the result is a heap corruption that can be leveraged for denial of service or arbitrary code execution. The flaw is an instance of unauthorized data deallocation (CWE‑843), escalating usage of memory to permit exploitation. The impact is focused on the Suricata instance processing the traffic, potentially exposing the host to destabilization or compromise.

Affected Systems

The vulnerability affects all OISF Suricata releases prior to version 8.0.7, which is the first release to contain the fix. All 8.x series installations that still run 8.0.6 or earlier are vulnerable. The vulnerability requires the configuration option app-layer.protocols.doh2 to be enabled, which is the default setting in the 8.x releases.

Risk and Exploitability

The CVSS score of 9.4 signals a critical severity, and although the EPSS score is not available, the lack of listing in the CISA KEV catalog does not diminish the potential for exploitation. The faulty code executes during normal network inspection of DoH traffic, so an attacker only needs to inject specially crafted traffic over the network to trigger the bug. Given that Suricata is commonly positioned as a network security sensor, the flaw poses a high risk to environments where it handles DoH connections.

Generated by OpenCVE AI on September 20, 2026 at 02:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.7 or later, which contains the fixed DoH2 handling logic.
  • If an upgrade cannot be performed immediately, configure app-layer.protocols.doh2 as false in suricata.yaml to disable DoH2 processing and prevent the type confusion from being triggered.
  • Continuously monitor Suricata logs for abnormal crashes or memory errors, and isolate the Suricata service from untrusted networks until the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Suricata DoH2 Type Confusion Leads to Invalid Free

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
First Time appeared Oisf
Oisf suricata
Weaknesses CWE-843
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
Vendors & Products Oisf
Oisf suricata
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:20:03.227Z

Reserved: 2026-09-20T01:18:05.348Z

Link: CVE-2026-94083

cve-icon Vulnrichment

Updated: 2026-09-22T15:19:59.809Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-20T02:16:53.520

Modified: 2026-09-28T18:30:00.563

Link: CVE-2026-94083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')