Security Advisory

CVE-2026-60108

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-09 14:16:57
Last updated 2026-07-14 22:03:32
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT control line. Attackers can exploit the NVT_Analyzer component's lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the Zeek sensor.