Vulnerabilities & PatchesEmerging1 src
CVE-2026-63447 - Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
CVE ID : CVE-2026-63447
Published : Sept. 18, 2026, 8:21 p. m.
• 35 minutes ago
Description : Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8. 0. 5 until 8. 0. 6, the FTP parser in src/app-layer-ftp. c can continue allocating transactions after app-layer. protocols. ftp. max-tx is reached while processing one large chunk of FTP command data.
The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8. 0. 6.
Severity: 0.0
• NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...