CVE-2026-63447 - Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
Brief
CVE ID : CVE-2026-63447
Published : Sept. 18, 2026, 8:21 p. m.
- 35 minutes ago
Description : Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.
- 5 until 8.
- 6, the FTP parser in src/app-layer-ftp. c can continue allocating transactions after app-layer. protocols. ftp. max-tx is reached while processing one large chunk of FTP command data.
The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8.
- 6.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
