Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-45764: Suricata may crash when handling HTTP/2 traffic
CVE-2026-45764 · published 29 days ago
Summary
Suricata versions before 7.0.16 and 8.0.5 can stop working if they receive specially crafted HTTP/2 data, which could shut down the monitoring service. Updating to version 7.0.16, 8.0.5 or later fixes the issue. If you cannot update right away, turn off HTTP/2 processing in Suricata’s settings.
What to do
- Update debian suricata to version 1:8.0.5-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | oisf | suricata |
>= 8.0.0, < 8.0.5 >= 7.0.0, < 7.0.16 |
| Ubuntu:16.04:LTS | canonical | suricata | All versions |
| Debian:13 | debian | suricata | All versions |
| Debian:14 | debian | suricata |
< 1:8.0.5-1 Fix: upgrade to 1:8.0.5-1
|
Original advisory text
Suricata http2: protocol-change type confusion can lead to denial of service
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 parsing if it is not required.
References
- https://github.com/OISF/suricata/security/advisories/GHSA-5rvq-72r5-rqhr Third Party Advisory
- https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315 Release Notes Vendor Advisory
- https://redmine.openinfosecfoundation.org/issues/8492 Permissions Required
- https://security-tracker.debian.org/tracker/CVE-2026-45764 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45764... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45764 Vendor Advisory
- https://github.com/OISF/suricata/commit/61c4df2821441226a2e0d3a5723f44ba95764cdd Third Party Advisory
- https://ubuntu.com/security/CVE-2026-45764 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-45764 Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/8494 Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/8493 Third Party Advisory
- https://github.com/OISF/suricata/commit/75a4641af6ee87a605e10557e6e2417330227a6a Third Party Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Type
CWE-843Type Confusion
Timeline
Published10 Sep 2026
Updated7 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-45764 · NVD
CVE-2026-45764 · MITRE
DEBIAN-CVE-2026-45764 · OSV
CVE-2026-45764 · OSV
GHSA-5rvq-72r5-rqhr · GHSA
UBUNTU-CVE-2026-45764 · OSV
Track software like this
Free during beta