Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Project Subscriptions

Vendors Products
Suricata Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Suricata’s HTTP/2 Response Header Processing

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
First Time appeared Oisf
Oisf suricata
Weaknesses CWE-416
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
Vendors & Products Oisf
Oisf suricata
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T18:27:33.350Z

Reserved: 2026-09-20T01:20:20.153Z

Link: CVE-2026-94084

cve-icon Vulnrichment

Updated: 2026-09-22T18:24:46.220Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-20T02:16:53.717

Modified: 2026-09-22T19:44:01.280

Link: CVE-2026-94084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses