PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45764 OISF CVE debrief

A critical vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could lead to a denial of service via crafted HTTP/2 traffic. This CVE was published on 2026-09-10T22:16:56.250Z and was last modified on 2026-09-11T18:24:59.400Z. The vulnerability, tracked as CVE-2026-45764, is due to a type confusion issue caused by a protocol change while processing HTTP/2 traffic. Crafted traffic may cause Suricata to crash, resulting in denial of service. The vulnerability has been addressed in Suricata versions 7.0.16 and 8.0.5. Evidence is limited to CVE and NVD records, with no specific information on exploitation

Vendor
OISF
Product
suricata
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-11
Advisory published
2026-09-10
Advisory updated
2026-09-11

Who should care

Network defenders and security teams responsible for managing Suricata installations should be aware of this vulnerability and take immediate action to patch or mitigate it. This includes reviewing current Suricata configurations, checking for exposure, and verifying that inventory is up-to-date.

Why it matters

CVE-2026-45764 is a critical vulnerability in Suricata that could lead to denial of service attacks via crafted HTTP/2 traffic. Defenders should prioritize patching to versions 7.0.16 or 8.0.5, or apply workarounds like disabling HTTP/2 parsing if immediate patching is not feasible. Evidence is limited to CVE and NVD records, with no specific information on exploitation or victim impact.

  • Potential denial of service via crafted HTTP/2 traffic
  • Necessity to verify Suricata configurations and inventory for exposure
  • Priority to patch or mitigate vulnerable Suricata installations
  • Possible need for temporary workarounds like disabling HTTP/2 parsing

Technical summary

Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, is vulnerable to a type confusion issue due to a protocol change while processing HTTP/2 traffic. This vulnerability, tracked as CVE-2026-45764, can be exploited by crafted traffic to cause Suricata to crash, resulting in a denial of service. The vulnerability has been addressed in Suricata versions 7.0.16 and 8.0.5.

Defensive priority

Defenders should prioritize patching Suricata installations to prevent potential denial of service attacks. Specifically, upgrading to versions 7.0.16 or 8.0.5 is recommended. If immediate patching is not feasible, disabling HTTP/2 parsing can serve as a temporary workaround.

Recommended defensive actions

  • Patch Suricata installations to versions 7.0.16 or 8.0.5
  • Disable HTTP/2 parsing as a temporary workaround if patching is not feasible
  • Monitor Suricata logs for potential exploitation attempts
  • Verify Suricata configurations and inventory for exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its critical CVSS score of 9.1 and the availability of patched versions. However, the corpus does not provide specific information on exploitation or victim impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45764 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45764

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45764 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45764

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.