Improper handling of exceptional conditions in Suricata - CVE-2026-63450

 

Improper handling of exceptional conditions in Suricata - CVE-2026-63450

Published: July 22, 2026


Vulnerability identifier: #VU139042
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-63450
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Open Information Security Foundation
Affected software:
Suricata

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass FTP parser-dependent detection and logging for later commands on the same TCP flow.

The vulnerability exists due to improper handling of exceptional conditions in the FTP parser when processing RETR or STOR commands before PORT or PASV negotiation. A remote attacker can send crafted FTP commands to bypass FTP parser-dependent detection and logging for later commands on the same TCP flow.

In IPS mode, the flow is dropped instead of continuing without application-layer detection.


How to mitigate CVE-2026-63450

Install security update from vendor's website.

Sources