Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-94084: Suricata can crash or be exploited during HTTP/2 inspection
CVE-2026-94084 · published 20 days ago
Summary
The Suricata network sensor (versions before 8.0.7) can run into a memory error when it checks HTTP/2 traffic that matches certain response‑header rules. This error could cause the service to stop working or allow an attacker to take control of the process. Upgrade Suricata to version 8.0.7 or later, or apply any official patch that fixes the problem.
What to do
- Update debian suricata to version 1:8.0.7-1.
- Update oisf suricata to version 8.0.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:13 | debian | suricata | All versions |
| Debian:14 | debian | suricata |
< 1:8.0.7-1 Fix: upgrade to 1:8.0.7-1
|
| Ubuntu:16.04:LTS | canonical | suricata | All versions |
| – | oisf | suricata | < 8.0.7 |
Original advisory text
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
References
- https://forum.suricata.io/t/suricata-8-0-7-released/6467 Release Notes
- https://github.com/OISF/suricata/commit/1d66355dc8737bb2ae7a198115b3067e3ad49808 Patch
- https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7 Release Notes
- https://ubuntu.com/security/CVE-2026-94084 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-94084 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94084... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-94084 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-94084 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-416Use After Free
Timeline
Published20 Sep 2026
Updated9 Oct 2026
First seen20 Sep 2026
Sources
CVE-2026-94084 · NVD
CVE-2026-94084 · MITRE
CVE-2026-94084 · OSV
UBUNTU-CVE-2026-94084 · OSV
DEBIAN-CVE-2026-94084 · OSV
Track software like this
Free during beta