CVE-2026-94084: Use After Free
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.responseheader with and without a transform.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Suricata versions before 8.0.7 are affected when HTTP/2 transactions are inspected by rules using http.response_header both with and without a transform.
What does an attacker need to exploit it?
The published vector indicates network-based exploitation with low attack complexity, no privileges, and no user interaction. The vulnerable condition is reached through HTTP/2 transaction inspection and the relevant rule configuration.
Are default Suricata rules necessarily affected?
The available information does not establish whether the default rule set contains the required combination of http.response_header rules. Exposure depends on rules that inspect a transaction using that keyword with and without a transform.
What should be done if immediate patching is not possible?
Review and limit rules that use http.response_header with and without a transform for HTTP/2 traffic until Suricata can be updated to 8.0.7 or later.