Junglewise Threat Intelligence

CVE-2026-60108: Zeek uncontrolled memory consumption in FTP analyzer

CVE-2026-60108 · Severity: high · CVSS 7.5 · Published 2026-07-09

Executive brief

Zeek is a popular network security monitoring platform used to analyze network traffic for threats. A vulnerability in its FTP analysis component allows a remote attacker to crash the monitoring sensor by sending specially crafted network traffic. This results in a denial-of-service, leaving the network unmonitored and potentially allowing other malicious activity to go undetected.

Technical details

An uncontrolled memory consumption vulnerability exists in the Zeek FTP analyzer's NVT_Analyzer component. The root cause is a lack of a maximum line length check when processing FTP control sessions. Specifically, when a session negotiates AUTH GSSAPI followed by a large ADAT control line, the analyzer continuously doubles its internal buffer without bounds during base64 decoding of the attacker-controlled ADAT token. This leads to memory exhaustion and process termination (Denial of Service). The vulnerability is reachable over the network without authentication. A fix is available in Zeek version 8.0.9, which introduces the InitBufferSafe method to enforce line length limits.

Affected products

  • Zeek Zeek < 8.0.9

Timeline

  • 2026-06-11: other: Initial patch authored
  • 2026-07-06: patched: Version 8.0.9 released
  • 2026-07-09: disclosed: CVE published

References

Related threats