Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-94084: Suricata can crash or be exploited during HTTP/2 inspection

CVE-2026-94084 · published 20 days ago
Summary

The Suricata network sensor (versions before 8.0.7) can run into a memory error when it checks HTTP/2 traffic that matches certain response‑header rules. This error could cause the service to stop working or allow an attacker to take control of the process. Upgrade Suricata to version 8.0.7 or later, or apply any official patch that fixes the problem.

What to do
  • Update debian suricata to version 1:8.0.7-1.
  • Update oisf suricata to version 8.0.7 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:13 debian suricata All versions
Debian:14 debian suricata < 1:8.0.7-1
Fix: upgrade to 1:8.0.7-1
Ubuntu:16.04:LTS canonical suricata All versions
– oisf suricata < 8.0.7
Original advisory text
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published20 Sep 2026
Updated9 Oct 2026
First seen20 Sep 2026
Track software like this
Free during beta