CVE-2026-45764: Suricata http2: protocol-change type confusion can lead to denial of service
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 parsing if it is not required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.5 - Configuration
Disable HTTP/2 parsing if it is not required (workaround).
Suricata HTTP/2 parsing HTTP/2 parsing = disabled
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Suricata deployments running versions earlier than 7.0.16 or 8.0.5 are affected when they process HTTP/2 traffic. The issue can cause the Suricata process to crash, disrupting its IDS, IPS, or network monitoring functions.
What does an attacker need to exploit it?
An attacker can send crafted HTTP/2 traffic that triggers a protocol change during processing. The supplied vector indicates network-based exploitation with low complexity and no privileges or user interaction required.
What can be done if upgrading is not immediately possible?
Disable HTTP/2 parsing if it is not required in the deployment. This is the documented workaround until Suricata can be updated to 7.0.16 or 8.0.5.