Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2026-45764

Suricata versions before 7.0.16 and 8.0.5 are vulnerable to a type‑confusion flaw when processing HTTP/2 traffic, which can be triggered by crafted packets to crash the engine and cause a denial‑of‑service. The issue is fixed in Suricata 7.0.16 and 8.0.5. As a temporary workaround, administrators can disable HTTP/2 parsing if it is not needed.

publishedSep 10, 2026
last modifiedSep 11, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
36th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 11, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Suricata users running versions earlier than 7.0.16 (7.x branch) or earlier than 8.0.5 (8.x branch).

02

Real-world impact

An attacker can send specially crafted HTTP/2 traffic to cause Suricata to crash, leading to loss of intrusion detection/prevention capabilities and a denial‑of‑service condition.

03

Why this severity

The CVSS v3.1 base score is 9.1 (Critical) due to low attack complexity, no privileges or user interaction required, and high impact on integrity and availability.

04

What to do about it

official fix available
recommended steps
  1. 011. Identify the Suricata major version in use (7.x or 8.x).
  2. 022. If running a 7.x release, upgrade Suricata to version 7.0.16 or later.
  3. 033. If running an 8.x release, upgrade Suricata to version 8.0.5 or later.
  4. 044. After upgrading, restart the Suricata service to apply the new version.
interim mitigations
  • Disable HTTP/2 parsing in Suricata if HTTP/2 inspection is not required for your environment.

NVD-referenced vendor advisory (fix versions 7.0.16 and 8.0.5 mentioned in the NVD description)

05

Timeline

  1. Sep 10, 2026 · 3d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Sep 11, 2026 · 3d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →