CRITICAL

CVE-2026-94084

2026-09-20 CVSS v3.1
CVSS
9.4

Description

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Weakness (CWE)

CWE-416 Use After Free

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE