Junglewise Threat Intelligence

CVE-2026-94084: Suricata use-after-free in HTTP/2 response header detection

CVE-2026-94084 · Severity: critical · CVSS 9.4 · Published 2026-09-20

Technologies: OISF Suricata. Vendors: OISF.

Executive brief

Suricata, an open-source network threat detection engine, contains a use-after-free vulnerability in its HTTP/2 response header processing. When security rules inspect the same HTTP transaction using response header keywords with and without text transformations, freed memory is accessed, potentially allowing remote attackers to crash the detection engine or execute arbitrary code.

Technical details

A use-after-free vulnerability exists in the Http2ThreadMultiBuf component when handling HTTP/2 response headers inspected by rules using the http.response_header keyword both with and without text transforms. The vulnerable code freed and reallocated buffers between inspection passes, leaving dangling pointers that were later dereferenced. The fix rewrites buffers in-place instead of deallocating and reallocating them, matching HTTP/1 behavior.

Affected products

  • OISF Suricata before 8.0.7

Timeline

  • 2026-09-15: disclosed
  • 2026-09-09: patched: Fix committed to main branch
  • 2026-09-20: advisory

References

Related threats