{"id":"CVE-2026-94083","published":"2026-09-20T02:16:53.520","lastModified":"2026-09-22T19:44:52.447","description":"Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.","cvssScore":9.4,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","cwes":["CWE-843"],"vendors":[],"products":[],"references":[{"url":"https://forum.suricata.io/t/suricata-8-0-7-released/6467","tags":[]},{"url":"https://github.com/OISF/suricata/commit/e574009add9c208f319e1d9d15b3bb1229c88074","tags":[]},{"url":"https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7","tags":[]}],"exploitRefs":[{"url":"https://github.com/OISF/suricata/commit/e574009add9c208f319e1d9d15b3bb1229c88074","tags":[]},{"url":"https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw in Suricata before 8.0.7 involves a DoH2 type confusion that can lead to an invalid free operation, impacting system stability and security.","exploitability":"Exploitation requires enabling the DoH2 protocol, which is default in 8.x versions, making it moderately easy for attackers with access to the service.","blast_radius":"If exploited, this could lead to denial of service or other security issues, impacting the affected system's availability and integrity.","remediation":"Upgrade to Suricata 8.0.7 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["dos","protocol-confusion","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:04:07.068Z"}}