CVE-2026-63450
Description
A flaw was found in Suricata, a network Intrusion Detection System (IDS) and Intrusion Prevention System (IPS). A remote attacker can exploit a vulnerability in the FTP parser where sending a RETR or STOR command before PORT or PASV negotiation is incorrectly treated as a fatal error. This error disables further FTP application-layer parsing for the duration of the TCP connection, allowing subsequent commands to bypass detection rules and logging in IDS mode, or causing the flow to be dropped in IPS mode. This can lead to a security bypass, enabling attackers to evade security monitoring.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
To mitigate this issue, configure Suricata to operate in Intrusion Prevention System (IPS) mode. In IPS mode, Suricata will drop TCP flows that exhibit the described FTP command sequence mishandling, thereby preventing the bypass of detection rules and logging. This configuration change typically requires restarting the Suricata service.
Understanding the Weakness (CWE)
Integrity,Other
Technical Impact: Unexpected State; Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.