External risk intelligence

Suricata DoH2 Type Confusion Invalid Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-94083

Suricata is a network security tool often placed at boundaries, but its specific deployment varies. While it processes network traffic, the vulnerability requires the DoH2 feature to be enabled and specific protocol conditions. Because Suricata's placement and configuration vary between edge monitoring, internal segmentation, and passive analysis, public reachability is not guaranteed.

Oisf Suricata

before 8.0.7

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Suricata network security technology could allow an attacker to cause disruptions if a specific protocol handling error occurs with DNS over HTTPS (DoH2) requests. While the technology is designed to monitor network traffic, the impact of this issue depends on how Suricata is configured and deployed within your environment. The primary concern is to confirm whether this specific functionality is enabled and if your deployment is exposed.

  • Type confusion impacts network traffic analysis.
  • Matters if the DoH2 feature is active.
  • Confirm Suricata DoH2 relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trigger this vulnerability by sending a specially crafted DoH2 request that attempts to upgrade from HTTP1 to HTTP2. This specific request manipulates the software's internal handling of connection types, leading to a critical error. When this error occurs, the software attempts to clean up resources incorrectly, potentially allowing an attacker to gain significant control over the affected system.

  • No special access needed.
  • DoH2 request with HTTP1 to HTTP2 upgrade.
  • Leads to code execution.

Live Threat

Current exploitation, exposure, and threat context

A type confusion in Suricata's DoH2 handling could lead to incorrect memory management when processing a specific sequence of HTTP requests, potentially affecting the integrity and availability of the Suricata service when app-layer DoH2 is enabled.

  • Network traffic inspection.
  • Malformed DoH2 requests with HTTP1 upgrade.
  • Service instability or crashes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Suricata product owner and the infrastructure team are likely responsible for addressing this vulnerability. The first practical step is to identify all deployed instances of Suricata, determine if the DoH2 feature is enabled, and assess their network exposure and criticality to prioritize remediation efforts.

  • Suricata product owner, infrastructure team.
  • Verify DoH2 feature, network exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Suricata?

Suricata is an open-source network security engine used for intrusion detection, prevention, and network traffic monitoring. It acts as a sensor to analyze traffic flows, identifying potential security threats by inspecting packets against pre-defined rules. Because it operates deep within network traffic, it is commonly deployed at network boundaries or within sensitive segments to provide visibility into data moving across an organization's infrastructure.

What is the CVE-2026-94083 type confusion vulnerability?

This vulnerability is a type confusion error classified as CWE-843. It occurs when Suricata incorrectly handles the internal state of a connection during a specific upgrade process. Essentially, the software mistakenly treats a connection as one type while it is actually another, leading to an 'invalid free' of system memory. This memory management failure can destabilize the software and potentially allow unauthorized control over the affected system.

How can an attacker trigger this vulnerability?

An attacker can trigger this issue by sending a specially crafted DNS over HTTPS (DoH2) request that attempts to upgrade from HTTP1 to HTTP2. This specific protocol sequence forces the software to misidentify the connection state. It is important to note that if the DoH2 feature is disabled in your Suricata configuration, or if traffic does not involve this specific HTTP upgrade sequence, the vulnerability cannot be triggered.

Is my network at risk from this vulnerability?

Halo Surface Signal indicates that risk depends on your specific deployment. Since Suricata is often placed at network edges or internal boundaries, your level of exposure varies. Because the bug requires the DoH2 feature to be enabled and depends on specific traffic patterns, not every instance is automatically reachable or affected. You must evaluate whether your specific Suricata sensors are exposed to untrusted traffic and have the DoH2 functionality active.

What should I do to address CVE-2026-94083?

Start by auditing your infrastructure to create an inventory of all running Suricata instances and their versions. For any version older than 8.0.7, determine if the DoH2 feature is enabled. Once identified, prioritize these instances based on their network exposure and role. Plan to update these systems to version 8.0.7 or later to resolve the underlying memory management error and restore system integrity.

References