← Back to search

CVE-2026-94084

9.4 CRITICALpublic exploit available

Published 2026-09-20 · Updated 2026-09-22

AI risk analysis

Summary
This flaw in Suricata before 8.0.7 involves a use-after-free vulnerability in the Http2ThreadMultiBuf handling, which can lead to potential memory corruption if exploited.
Exploitability
Exploitation requires specific Suricata rule configurations and HTTP transactions, making it moderately difficult to exploit.
Blast radius
If exploited, this vulnerability could lead to denial of service or potentially arbitrary code execution, depending on the environment and mitigations in place.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Suricata 8.0.7 or later.
use-after-freehttp2suricata

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Weaknesses

CWE-416

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.