
🚨 TWO CRITICAL SURICATA FLAWS DISCLOSED — CRAFTED TRAFFIC CAN CRASH THE IDS/IPS Two newly assigned critical vulnerabilities in Suricata 8.x expose the network-monitoring engine itself to unauthenticated, network-triggered memory corruption. • CVE-2026-94083 — CVSS 9.4 — DoH2 type confusion / invalid free • CVE-2026-94084 — CVSS 9.4 — HTTP/2 use-after-free • Both affect Suricata versions before 8.0.7 • CVE-2026-94083 requires app-layer.protocols.doh2, which is enabled by default in Suricata 8.x • Crafted traffic can trigger memory corruption and crash the Suricata process, potentially creating a monitoring blind spot • No public PoC or confirmed in-the-wild exploitation has been identified at this time • Fixed in Suricata 8.0.7 ⚠️ Analyst Note: The unusual security angle is that an attacker can target the defensive sensor using traffic the sensor is supposed to inspect. A successful crash could temporarily remove IDS/IPS visibility while subsequent malicious activity crosses the monitored segment. Suricata 8.0.7 is a broader security release addressing the project's highest number of vulnerability reports to date. OISF says the increase was partly driven by AI-assisted security analysis. Original OISF release: https://suricata.io/2026/09/15/suricata-8-0-7-released/ #Suricata #IDS #IPS #Vulnerability #CyberSecurity #ThreatIntel #DDW #DarkWeb


