CVE-2026-45764
Suricata versions before 7.0.16 and 8.0.5 are vulnerable to a type‑confusion flaw when processing HTTP/2 traffic, which can be triggered by crafted packets to crash the engine and cause a denial‑of‑service. The issue is fixed in Suricata 7.0.16 and 8.0.5. As a temporary workaround, administrators can disable HTTP/2 parsing if it is not needed.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Suricata users running versions earlier than 7.0.16 (7.x branch) or earlier than 8.0.5 (8.x branch).
Real-world impact
An attacker can send specially crafted HTTP/2 traffic to cause Suricata to crash, leading to loss of intrusion detection/prevention capabilities and a denial‑of‑service condition.
Why this severity
The CVSS v3.1 base score is 9.1 (Critical) due to low attack complexity, no privileges or user interaction required, and high impact on integrity and availability.
What to do about it
- 011. Identify the Suricata major version in use (7.x or 8.x).
- 022. If running a 7.x release, upgrade Suricata to version 7.0.16 or later.
- 033. If running an 8.x release, upgrade Suricata to version 8.0.5 or later.
- 044. After upgrading, restart the Suricata service to apply the new version.
- ›Disable HTTP/2 parsing in Suricata if HTTP/2 inspection is not required for your environment.
NVD-referenced vendor advisory (fix versions 7.0.16 and 8.0.5 mentioned in the NVD description)
Timeline
- Sep 10, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 11, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.