Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-45764: Suricata may crash when handling HTTP/2 traffic

CVE-2026-45764 · published 29 days ago
Summary

Suricata versions before 7.0.16 and 8.0.5 can stop working if they receive specially crafted HTTP/2 data, which could shut down the monitoring service. Updating to version 7.0.16, 8.0.5 or later fixes the issue. If you cannot update right away, turn off HTTP/2 processing in Suricata’s settings.

What to do
  • Update debian suricata to version 1:8.0.5-1.
Affected software
Ecosystem VendorProductAffected versions
– oisf suricata >= 8.0.0, < 8.0.5
>= 7.0.0, < 7.0.16
Ubuntu:16.04:LTS canonical suricata All versions
Debian:13 debian suricata All versions
Debian:14 debian suricata < 1:8.0.5-1
Fix: upgrade to 1:8.0.5-1
Original advisory text
Suricata http2: protocol-change type confusion can lead to denial of service
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 parsing if it is not required.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-843Type Confusion
Timeline
Published10 Sep 2026
Updated7 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta