Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Detection Bypass
Action: Immediate Patch
AI Analysis

Impact

The Suricata SMTP MIME parser fails to fully reset state for message/rfc822 encapsulation, allowing outer MIME part encoding or filename attributes to leak into the inner message. This weakness, classified as CWE‑665, permits an attacker to craft an email that bypasses detection rules based on file.data, file.name, or extracted URLs when SMTP MIME decoding is active. An attacker could thus deliver malicious attachments or malicious URLs that slip through monitoring security controls, degrading the integrity and confidentiality of the monitored traffic.

Affected Systems

The issue affects Suricata 8.0.0 through 8.0.5 (inclusive) released by the Open Information Security Foundation. Versions 8.0.6 and newer contain the fix. Vendors relying on the open source Suricata engine and using SMTP MIME decoding must verify their deployed versions against this range.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve sending specially constructed SMTP traffic that leverages message/rfc822 encapsulation via compromised or rogue mail servers. An adversary could use this to subvert detection of file attachments or URLs, potentially aiding phishing or malware distribution campaigns.

Generated by OpenCVE AI on September 19, 2026 at 10:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading to Suricata 8.0.6 or newer.
  • If upgrading is delayed, immediately disable SMTP MIME decoding to prevent state leakage exploitation.
  • Monitor logs for malicious MIME content and adjust detection rules to account for potential bypass until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Sat, 26 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6.
Title Suricata smtp/mime: incomplete state reset allows detection bypass
Weaknesses CWE-665
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-25T19:21:41.030Z

Reserved: 2026-06-24T02:21:33.811Z

Link: CVE-2026-57229

cve-icon Vulnrichment

Updated: 2026-09-25T19:21:35.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:01.537

Modified: 2026-09-28T18:35:07.867

Link: CVE-2026-57229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:16Z

Weaknesses