Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-94083: Suricata may crash handling certain DNS‑over‑HTTPS requests
CVE-2026-94083 · published 20 days ago
Summary
The Suricata network monitoring tool can stop working if it processes a DNS‑over‑HTTPS request that tries to switch from HTTP 1 to HTTP 2. This happens because the program frees memory incorrectly when the upgrade is attempted. Update Suricata to version 8.0.7 or later, or disable the DoH2 feature if you cannot upgrade.
What to do
- Update debian suricata to version 1:8.0.7-1.
- Update oisf suricata to version 8.0.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:13 | debian | suricata | All versions |
| Debian:14 | debian | suricata |
< 1:8.0.7-1 Fix: upgrade to 1:8.0.7-1
|
| Ubuntu:16.04:LTS | canonical | suricata | All versions |
| – | oisf | suricata | < 8.0.7 |
Original advisory text
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 requ...
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
References
- https://forum.suricata.io/t/suricata-8-0-7-released/6467 Release Notes
- https://github.com/OISF/suricata/commit/e574009add9c208f319e1d9d15b3bb1229c88074 Patch
- https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7 Release Notes
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94083... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-94083 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-94083 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-94083 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-94083 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-843Type Confusion
Timeline
Published20 Sep 2026
Updated9 Oct 2026
First seen20 Sep 2026
Sources
CVE-2026-94083 · NVD
CVE-2026-94083 · MITRE
CVE-2026-94083 · OSV
UBUNTU-CVE-2026-94083 · OSV
DEBIAN-CVE-2026-94083 · OSV
Track software like this
Free during beta