SEPTEMBER 29, 2026
Live Feed
Back to database
Case File

CVE-2026-63450

LOW · CVSS 3.7 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-29

CyberRota Analysis

AI-Generated

The FTP parser in Suricata versions prior to 8.0.6 is vulnerable to improper handling of RETR or STOR commands sent before PORT or PASV negotiations, leading to a fatal application-layer error that disables further FTP parsing. This can result in the evasion of parser-dependent rules and logging, potentially allowing malicious commands to go undetected. Organizations using Suricata for network security should prioritize upgrading to version 8.0.6 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63450
Severity
LOW
CVSS
3.7
EPSS
N/A

Original NVD Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.

Related CVEs

Other vulnerabilities affecting the same vendor(s)