PT-2026-95902 · Suricata · Suricata

CVE-2026-94083

·

Published

2026-09-20

·

Updated

2026-09-22

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 8.0.7
Description A type confusion exists in the handling of DoH2 (DNS over HTTP/2) when a DoH2 request occurs during an HTTP1 to HTTP2 upgrade. This issue occurs because the cleanup code for the HTTP2 state is executed while the actual state remains HTTP1, leading to an invalid free. This condition can cause the Intrusion Detection System (IDS) to crash. The issue requires the app-layer.protocols.doh2 setting to be enabled, which is the default configuration in 8.x versions.
Recommendations Update to version 8.0.7. As a temporary mitigation, disable the app-layer.protocols.doh2 feature.

Exploit

Fix

DoS

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94083

Affected Products

Suricata