CVE-2026-94083

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-20); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-20: 3Mentions · 2026-09-21: 109-2009-21
Referenced assets3 URLs
Full discourse4 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 TWO CRITICAL SURICATA FLAWS DISCLOSED — CRAFTED TRAFFIC CAN CRASH THE IDS/IPS Two newly assigned critical vulnerabilities in Suricata 8.x expose the network-monitoring engine itself to unauthenticated, network-triggered memory corruption. • CVE-2026-94083 — CVSS 9.4 — DoH2 type confusion / invalid free • CVE-2026-94084 — CVSS 9.4 — HTTP/2 use-after-free • Both affect Suricata versions before 8.0.7 • CVE-2026-94083 requires app-layer.protocols.doh2, which is enabled by default in Suricata 8.x • Crafted traffic can trigger memory corruption and crash the Suricata process, potentially creating a monitoring blind spot • No public PoC or confirmed in-the-wild exploitation has been identified at this time • Fixed in Suricata 8.0.7 ⚠️ Analyst Note: The unusual security angle is that an attacker can target the defensive sensor using traffic the sensor is supposed to inspect. A successful crash could temporarily remove IDS/IPS visibility while subsequent malicious activity crosses the monitored segment. Suricata 8.0.7 is a broader security release addressing the project's highest number of vulnerability reports to date. OISF says the increase was partly driven by AI-assisted security analysis. Original OISF release: https://suricata.io/2026/09/15/suricata-8-0-7-released/ #Suricata #IDS #IPS #Vulnerability #CyberSecurity #ThreatIntel #DDW #DarkWeb

    010434.5K
    204.6K followersView on X
  • VulnTracker@vuln_tracker

    A default-enabled Suricata feature can crash your IDS with a single crafted connection (CVSS 9.4). CVE-2026-94083 is a type confusion in Suricata's DoH2 handling when a DoH2 request rides an HTTP1-to-HTTP2 upgrade, the wrong cleanup code runs and triggers an invalid free. DoH2 is enabled by default in Suricata 8.x. Fixed in Suricata 8.0.7. Update now. Details: http://vulntracker.io/cves/CVE-2026-94083 #Suricata #CVE #IDS #InfoSec #CyberSecurity

    00031197
    756 followersView on X
  • VulnTracker@vuln_tracker

    Suricata's HTTP2 engine had two critical memory-safety bugs at once both fixed in a single release. CVE-2026-94083 is a DoH2 type confusion causing an invalid free. CVE-2026-94084 is a separate Http2ThreadMultiBuf use-after-free triggered by http.response_header rules. Both are rated 9.4 and both affect Suricata before 8.0.7. One update closes both. Update now. Details: http://vulntracker.io/cves/CVE-2026-94083 #Suricata #CVE #IDS #InfoSec #CyberSecurity

    00030144
    756 followersView on X
  • ADK Cyber@ADKCyber

    CVE-2026-94083 (CVSS 9.4): Suricata < 8.0.7 vulnerable to invalid free via DoH2 handling. Upgrade to 8.0.7 if using for detection. https://nvd.nist.gov/vuln/detail/CVE-2026-94083 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/1SFetGvc0T

    0000026
    96 followersView on X

Explore more