PatchSiren cyber security CVE debrief
CVE-2026-45764 OISF CVE debrief
A critical vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could lead to a denial of service via crafted HTTP/2 traffic. This CVE was published on 2026-09-10T22:16:56.250Z and was last modified on 2026-09-11T18:24:59.400Z. The vulnerability, tracked as CVE-2026-45764, is due to a type confusion issue caused by a protocol change while processing HTTP/2 traffic. Crafted traffic may cause Suricata to crash, resulting in denial of service. The vulnerability has been addressed in Suricata versions 7.0.16 and 8.0.5. Evidence is limited to CVE and NVD records, with no specific information on exploitation
- Vendor
- OISF
- Product
- suricata
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-11
Who should care
Network defenders and security teams responsible for managing Suricata installations should be aware of this vulnerability and take immediate action to patch or mitigate it. This includes reviewing current Suricata configurations, checking for exposure, and verifying that inventory is up-to-date.
Why it matters
CVE-2026-45764 is a critical vulnerability in Suricata that could lead to denial of service attacks via crafted HTTP/2 traffic. Defenders should prioritize patching to versions 7.0.16 or 8.0.5, or apply workarounds like disabling HTTP/2 parsing if immediate patching is not feasible. Evidence is limited to CVE and NVD records, with no specific information on exploitation or victim impact.
- Potential denial of service via crafted HTTP/2 traffic
- Necessity to verify Suricata configurations and inventory for exposure
- Priority to patch or mitigate vulnerable Suricata installations
- Possible need for temporary workarounds like disabling HTTP/2 parsing
Technical summary
Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, is vulnerable to a type confusion issue due to a protocol change while processing HTTP/2 traffic. This vulnerability, tracked as CVE-2026-45764, can be exploited by crafted traffic to cause Suricata to crash, resulting in a denial of service. The vulnerability has been addressed in Suricata versions 7.0.16 and 8.0.5.
Defensive priority
Defenders should prioritize patching Suricata installations to prevent potential denial of service attacks. Specifically, upgrading to versions 7.0.16 or 8.0.5 is recommended. If immediate patching is not feasible, disabling HTTP/2 parsing can serve as a temporary workaround.
Recommended defensive actions
- Patch Suricata installations to versions 7.0.16 or 8.0.5
- Disable HTTP/2 parsing as a temporary workaround if patching is not feasible
- Monitor Suricata logs for potential exploitation attempts
- Verify Suricata configurations and inventory for exposure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its critical CVSS score of 9.1 and the availability of patched versions. However, the corpus does not provide specific information on exploitation or victim impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45764 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45764
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45764 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45764
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
-
Source reference
Unverified legacy reference
URL: https://github.com/OISF/suricata/security/advisories/GHSA-5rvq-72r5-rqhr
-
Source reference
Unverified legacy reference
URL: https://redmine.openinfosecfoundation.org/issues/8492
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.