CVE-2026-94084: Oisf Suricata
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
Affected products
- Oisf Suricata: before 8.0.7 (fixed in 8.0.7)
Published 2026-09-20. Last modified 2026-09-28.