5.3
CVE-2026-57229
- EPSS 0.41%
- Veröffentlicht 18.09.2026 20:18:38
- Zuletzt bearbeitet 28.09.2026 18:35:07
- Erkennungen
Suricata smtp/mime: incomplete state reset allows detection bypass
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.352 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-665 Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
https://github.com/OISF/suricata/security/advisories/GHSA-ph5p-pm8r-m355
https://github.com/OISF/suricata/commit/4985eb9daea2f765b6ef59a58fa02e5c71c0a77c
https://github.com/OISF/suricata/commit/c0215c7e175b0000ef8450928dd1f3453c48379b
https://redmine.openinfosecfoundation.org/issues/8649