Vulnerability in Suricata's FTP Parsing Affects Network Security Monitoring
CVE-2026-63450
3.7LOW
What is CVE-2026-63450?
A vulnerability exists in Suricata's FTP parser that incorrectly handles RETR or STOR commands sent before the required PORT or PASV negotiations. Instead of dealing with this as a recoverable event, the parser treats it as a fatal error, leading to the disabling of FTP application-layer rules and logging during the entire TCP flow. This allows subsequent commands to bypass critical security measures, impacting the integrity of intrusion detection and prevention efforts. The issue has been resolved in Suricata version 8.0.6.
Affected Version(s)
suricata < 8.0.6
