Description
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to potential arbitrary code execution or crashes
Action: Immediate Patch
AI Analysis

Impact

Suricata versions prior to 8.0.7 contain a use‑after‑free flaw in the Http2ThreadMultiBuf component that is triggered when a transaction is examined by rules using http.response_header, whether a transform is applied or not. The bug can cause memory corruption, resulting in a process crash or, depending on the execution context, execution of arbitrary code, which would compromise the integrity and availability of the network monitoring system. The weakness is classified as CWE‑416 and the CVSS score of 9.4 indicates a critical severity.

Affected Systems

Affected are all installations of Suricata from the OISF project that are running version 8.0.6 or earlier. No specific patch level or product sub‑variant is listed beyond the overall 8.0.6/8.0.7 distinction, so any deployment of Suricata 8.0.6 or older is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.4 reflects high exploit potential, but the EPSS score is currently not available, so precise likelihood of exploitation in the wild is unknown. The vulnerability is not yet listed in CISA’s KEV catalog. The most likely attack vector is a malicious HTTP/2 transaction crafted to trigger the rule engine, which is a remote attack if the Suricata instance is exposed to untrusted traffic. Because the flaw is triggered by rule matching, an attacker could construct a payload that forces the rule engine to parse a header that leads to the use‑after‑free, potentially including a malicious transform. Without a patch, the system is at imminent risk of compromise or denial of service.

Generated by OpenCVE AI on September 20, 2026 at 02:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.7 or later to obtain the patch that fixes the use‑after‑free bug.
  • Temporarily modify the Suricata rule set or configuration to disable rules that use http.response_header for HTTP/2 traffic, or disable the HTTP/2 module entirely while the patch is pending.
  • If the server must handle HTTP/2 traffic, route untrusted traffic through a firewall or proxy that blocks or limits HTTP/2 to protect the Suricata instance until a fix is applied.

Generated by OpenCVE AI on September 20, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Suricata’s HTTP/2 Response Header Processing

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
First Time appeared Oisf
Oisf suricata
Weaknesses CWE-416
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
Vendors & Products Oisf
Oisf suricata
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T18:27:33.350Z

Reserved: 2026-09-20T01:20:20.153Z

Link: CVE-2026-94084

cve-icon Vulnrichment

Updated: 2026-09-22T18:24:46.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-20T02:16:53.717

Modified: 2026-09-28T18:29:51.570

Link: CVE-2026-94084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses