Bug 2538145 (CVE-2026-63450)

Summary: CVE-2026-63450 Suricata: Suricata: Security bypass via FTP command sequence mishandling
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Suricata, a network Intrusion Detection System (IDS) and Intrusion Prevention System (IPS). A remote attacker can exploit a vulnerability in the FTP parser where sending a `RETR` or `STOR` command before `PORT` or `PASV` negotiation is incorrectly treated as a fatal error. This error disables further FTP application-layer parsing for the duration of the TCP connection, allowing subsequent commands to bypass detection rules and logging in IDS mode, or causing the flow to be dropped in IPS mode. This can lead to a security bypass, enabling attackers to evade security monitoring.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539198, 2539200    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 17:17:41 UTC
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.