CRITICAL 9.4 NVD
CVE-2026-94084
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transf
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
References
- https://forum.suricata.io/t/suricata-8-0-7-released/6467
- https://github.com/OISF/suricata/commit/1d66355dc8737bb2ae7a198115b3067e3ad49808
- https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-20 via NVD.
Risk Timeline
CVE Disclosed2026-09-20 · -1 days ago
Remediation Resources
vulnfeed aggregates 14150 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.