Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 20 Sep 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Suricata DoH2 Type Confusion Leads to Invalid Free |
Sun, 20 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions. | |
| First Time appeared |
Oisf
Oisf suricata |
|
| Weaknesses | CWE-843 | |
| CPEs | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oisf
Oisf suricata |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-20T01:18:05.744Z
Reserved: 2026-09-20T01:18:05.348Z
Link: CVE-2026-94083
No data.
Status : Received
Published: 2026-09-20T02:16:53.520
Modified: 2026-09-20T02:16:53.520
Link: CVE-2026-94083
No data.
OpenCVE Enrichment
Updated: 2026-09-20T03:30:13Z
Weaknesses