Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Detection Evasion
Action: Patch
AI Analysis

Impact

Suricata's FTP parser incorrectly treats a RETR or STOR command issued before the data transfer mode negotiation (PORT or PASV) as a fatal application‑layer error. This causes the parser to enter a fatal state and disables further FTP parsing for the entire remaining TCP flow. As a result, any subsequent FTP commands pass through the IDS/IPS engine without application‑layer inspection, allowing an attacker to evade parser‑dependent detection rules or logging. The vulnerability does not grant direct code execution but reduces the effectiveness of IDS/IPS monitoring for the affected session.

Affected Systems

OISF Suricata versions earlier than 8.0.6 are impacted. The flaw resides in the FTP component of the Suricata engine and was corrected in the 8.0.6 release.

Risk and Exploitability

The CVSS score of 3.7 indicates moderate severity. EPSS is unavailable and the issue is not listed in CISA’s KEV catalogue. The vulnerability can be exploited by any external party that can establish an FTP session to the Suricata‑protected network. By sending a RETR or STOR command before initiating data transfer mode, an attacker can force Suricata to discard further session inspection, thereby suppressing detection of later commands. The attack does not require privileged access to the Suricata host, and the impact is limited to the specific file transfer session.

Generated by OpenCVE AI on September 19, 2026 at 11:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.6 or later.
  • If an upgrade cannot be performed immediately, isolate FTP traffic from Suricata inspection or disable FTP application‑layer parsing for the affected network segment to prevent detection evasion.
  • Continuously monitor logs for unusual FTP activity and re‑load Suricata configuration after applying changes.

Generated by OpenCVE AI on September 19, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.
Title Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T19:45:34.656Z

Reserved: 2026-07-16T19:35:57.768Z

Link: CVE-2026-63450

cve-icon Vulnrichment

Updated: 2026-09-23T19:45:29.763Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:04.370

Modified: 2026-09-28T18:33:07.807

Link: CVE-2026-63450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-755

    Improper Handling of Exceptional Conditions