Type Confusion Vulnerability in Suricata by Open Information Security Foundation
CVE-2026-94083
9.4CRITICAL
What is CVE-2026-94083?
There is a type confusion vulnerability in Suricata versions prior to 8.0.7. The issue arises from a flaw in the handling of DoH2 requests that can lead to an invalid memory free. Specifically, this occurs when the cleanup code for the HTTP2 state is triggered while the actual state remains in HTTP1 during a DoH2 request with an upgrade. This security concern affects users who have enabled the app-layer.protocols.doh2 feature, which is enabled by default in the 8.x branch. It is crucial for users to upgrade to version 8.0.7 to protect against this vulnerability.
Affected Version(s)
Suricata 8.0.0 < 8.0.7
