7.5
CVE-2026-63447
- EPSS 0.36%
- Veröffentlicht 18.09.2026 20:21:06
- Zuletzt bearbeitet 28.09.2026 18:34:20
- Erkennungen
Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8.0.6.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.299 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-407 Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
https://github.com/OISF/suricata/security/advisories/GHSA-w394-3g33-3jg9
https://github.com/OISF/suricata/commit/15bf91c5ccbbbf640cd042e1c96974b262549385
https://github.com/OISF/suricata/commit/82c41905589305e8389ceb793907ccb74798aee5
https://redmine.openinfosecfoundation.org/issues/8592