Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-94083: Suricata may crash handling certain DNS‑over‑HTTPS requests

CVE-2026-94083 · published 20 days ago
Summary

The Suricata network monitoring tool can stop working if it processes a DNS‑over‑HTTPS request that tries to switch from HTTP 1 to HTTP 2. This happens because the program frees memory incorrectly when the upgrade is attempted. Update Suricata to version 8.0.7 or later, or disable the DoH2 feature if you cannot upgrade.

What to do
  • Update debian suricata to version 1:8.0.7-1.
  • Update oisf suricata to version 8.0.7 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:13 debian suricata All versions
Debian:14 debian suricata < 1:8.0.7-1
Fix: upgrade to 1:8.0.7-1
Ubuntu:16.04:LTS canonical suricata All versions
– oisf suricata < 8.0.7
Original advisory text
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 requ...
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-843Type Confusion
Timeline
Published20 Sep 2026
Updated9 Oct 2026
First seen20 Sep 2026
Track software like this
Free during beta