CVE-2026-94083

CRITICAL CVSS 3.1: 9.4 EPSS 0.54%
Updated Sep 22, 2026
Oisf
Parameter Value
CVSS 9.4 (CRITICAL)
Affected Versions 8.0.0 — 8.0.7
Fixed In 8.0.7
Type CWE-843 (Type Confusion)
Vendor Oisf
Public PoC No

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Oisf Suricata
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
8.0.0 8.0.7