Executive brief
Zeek is a popular network security monitoring platform used to analyze network traffic for threats. A vulnerability in its FTP analysis component allows a remote attacker to crash the monitoring sensor by sending specially crafted network traffic. This results in a denial-of-service, leaving the network unmonitored and potentially allowing other malicious activity to go undetected.
Technical details
An uncontrolled memory consumption vulnerability exists in the Zeek FTP analyzer's NVT_Analyzer component. The root cause is a lack of a maximum line length check when processing FTP control sessions. Specifically, when a session negotiates AUTH GSSAPI followed by a large ADAT control line, the analyzer continuously doubles its internal buffer without bounds during base64 decoding of the attacker-controlled ADAT token. This leads to memory exhaustion and process termination (Denial of Service). The vulnerability is reachable over the network without authentication. A fix is available in Zeek version 8.0.9, which introduces the InitBufferSafe method to enforce line length limits.
Affected products
- Zeek Zeek < 8.0.9
Timeline
- 2026-06-11: other: Initial patch authored
- 2026-07-06: patched: Version 8.0.9 released
- 2026-07-09: disclosed: CVE published