CVE-2026-45764
largeType Confusion DoS in Suricata HTTP/2 Traffic Processing
Suricata, the open-source network Intrusion Detection/Prevention and Network Security Monitoring engine, contains a type confusion flaw (CWE-843) in its HTTP/2 handling that occurs when a protocol change is processed during traffic inspection. An attacker who can send crafted HTTP/2 traffic across a link monitored by Suricata can trigger the flaw without authentication or user interaction, crashing the engine and causing denial of service. The CVSS 9.1 (critical) rating reflects high integrity and availability impact with no confidentiality loss, and the crash risk is especially serious for inline IPS deployments where sensor failure disrupts inspection. All Suricata versions prior to 7.0.16 (7.0.x branch) and prior to 8.0.5 (8.0.x branch) are affected. No public proof-of-concept or in-the-wild exploitation is currently known, and the issue is not in CISA's KEV catalog.
What to do: Upgrade Suricata to 7.0.16 (7.0.x branch) or 8.0.5 (8.0.x branch), including patched builds supplied by appliance or distribution vendors that bundle the engine. If upgrading is not immediately possible, disable HTTP/2 parsing where it is not required, as this is the documented workaround. Prioritize inline IPS deployments, where a crash from crafted HTTP/2 traffic has the greatest operational impact.
| OISF (Suricata project) Suricata | All versions prior to 7.0.16 (7.0.x branch) and prior to 8.0.5 (8.0.x branch); fixed in 7.0.16 and 8.0.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 parsing if it is not required.
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.