← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 20:21via CVEFeed

CVE-2026-63447 - Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption

Brief

CVE ID : CVE-2026-63447

Published : Sept. 18, 2026, 8:21 p. m.

  • 35 minutes ago

Description : Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.

  • 5 until 8.
  • 6, the FTP parser in src/app-layer-ftp. c can continue allocating transactions after app-layer. protocols. ftp. max-tx is reached while processing one large chunk of FTP command data.

The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8.

  • 6.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→