Always-Incorrect Control Flow Implementation in Suricata - #VU152928
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass FTP-specific inspection and enforcement.
The vulnerability exists due to always-incorrect control flow implementation in the FTP application-layer parser when processing an overlong FTP command or reply followed by a complete FTP line in the same stream slice. A remote attacker can send a crafted FTP control line sequence to bypass FTP-specific inspection and enforcement.
Raw stream inspection remains active, but FTP data-channel recognition, file extraction, and filestore may be bypassed.