Type Confusion Vulnerability in Suricata by Open Information Security Foundation
CVE-2026-94083

9.4CRITICAL

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-94083?

There is a type confusion vulnerability in Suricata versions prior to 8.0.7. The issue arises from a flaw in the handling of DoH2 requests that can lead to an invalid memory free. Specifically, this occurs when the cleanup code for the HTTP2 state is triggered while the actual state remains in HTTP1 during a DoH2 request with an upgrade. This security concern affects users who have enabled the app-layer.protocols.doh2 feature, which is enabled by default in the 8.x branch. It is crucial for users to upgrade to version 8.0.7 to protect against this vulnerability.

Affected Version(s)

Suricata 8.0.0 < 8.0.7

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.