{"id":"CVE-2026-94084","published":"2026-09-20T02:16:53.717","lastModified":"2026-09-22T19:44:01.280","description":"Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.","cvssScore":9.4,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://forum.suricata.io/t/suricata-8-0-7-released/6467","tags":[]},{"url":"https://github.com/OISF/suricata/commit/1d66355dc8737bb2ae7a198115b3067e3ad49808","tags":[]},{"url":"https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7","tags":[]}],"exploitRefs":[{"url":"https://github.com/OISF/suricata/commit/1d66355dc8737bb2ae7a198115b3067e3ad49808","tags":[]},{"url":"https://github.com/OISF/suricata/compare/suricata-8.0.6...suricata-8.0.7","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw in Suricata before 8.0.7 involves a use-after-free vulnerability in the Http2ThreadMultiBuf handling, which can lead to potential memory corruption if exploited.","exploitability":"Exploitation requires specific Suricata rule configurations and HTTP transactions, making it moderately difficult to exploit.","blast_radius":"If exploited, this vulnerability could lead to denial of service or potentially arbitrary code execution, depending on the environment and mitigations in place.","remediation":"Upgrade to Suricata 8.0.7 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["use-after-free","http2","suricata"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:04:01.291Z"}}