PT-2026-95903 · Suricata · Suricata

CVE-2026-94084

·

Published

2026-09-20

·

Updated

2026-09-22

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 8.0.7
Description A use-after-free flaw exists in the Http2ThreadMultiBuf component. This occurs when the system inspects HTTP/2 transactions using rules that apply http.response header both with and without a transform. A use-after-free is a memory corruption issue where the software continues to use a memory address after it has been freed. This can be triggered by unauthenticated attackers sending crafted HTTP/2 traffic, potentially leading to process crashes or arbitrary code execution.
Recommendations Update Suricata to version 8.0.7 or higher.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94084

Affected Products

Suricata