Skip to content
Critical Suricata Flaws Allow Network Crashes

Critical Suricata Flaws Allow Network Crashes

First seen 20 Sep 2026, 21:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 21:58 UTC
  • Two critical vulnerabilities in Suricata released on September 20, 2026.
  • CVE-2026-94084 and CVE-2026-94083 allow unauthenticated attackers to crash the IDS/IPS.
  • Suricata 8.0.7 is available to patch these vulnerabilities.

On September 20, 2026, the OISF released Suricata 8.0.7 to address two critical vulnerabilities, CVE-2026-94084 and CVE-2026-94083, both with a CVSS score of 9.4. These flaws allow unauthenticated attackers to crash the Suricata IDS/IPS, bypassing network monitoring. CVE-2026-94084 is a use-after-free vulnerability in HTTP/2 inspection, while CVE-2026-94083 involves type confusion in the DoH2 parser. Both vulnerabilities affect all Suricata versions prior to 8.0.7. The flaws expose significant risks, especially in environments using default configurations. Organizations are urged to update to the latest version to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-20
Suricata 8.0.7 released
OISF released an update to address two critical vulnerabilities affecting all prior versions.
Cryptorank
2026-09-20
CVE-2026-94084 published
A use-after-free vulnerability in HTTP/2 inspection was disclosed, affecting all versions before 8.0.7.
Forkast.News
2026-09-20
CVE-2026-94083 published
A type confusion vulnerability in DoH2 parsing was disclosed, also affecting all versions before 8.0.7.
Forkast.News

More articles in this cluster (5)

Following this threat?

Track CVE-2026-94083 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed