CVE-2026-60108

Source
https://cve.org/CVERecord?id=CVE-2026-60108
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-60108.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-60108
Published
2026-07-09T14:16:57.988Z
Modified
2026-08-12T03:51:09.274956678Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer
Details

Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT control line. Attackers can exploit the NVT_Analyzer component's lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the Zeek sensor.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60108.json"
}
References

Affected packages

Git / github.com/zeek/zeek

Affected ranges

Type
GIT
Repo
https://github.com/zeek/zeek
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:zeek:zeek:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.0.9"
        }
    ]
}

Affected versions

Other
beta
lts
release
v1.*
v1.1
v1.6-dev
v2.*
v2.0
v2.0-beta
v2.0-beta-pre
v2.1
v2.1-beta
v2.2
v2.2-beta
v2.3
v2.3-beta
v2.4
v2.4-beta
v2.5
v2.5-beta
v2.5-beta2
v2.6
v2.6-beta2
v2.6-beta3
v3.*
v3.1.0-dev
v3.2.0-dev
v3.3.0-dev
v4.*
v4.1.0-dev
v4.2.0-dev
v5.*
v5.0.0-dev
v5.1.0-dev
v5.2.0-dev
v6.*
v6.0.0-dev
v6.1.0-dev
v6.2.0-dev
v7.*
v7.0.0-dev
v7.1.0-dev
v7.2.0-dev
v8.*
v8.0.0
v8.0.0-dev
v8.0.0-rc1
v8.0.0-rc2
v8.0.1
v8.0.2
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-60108.json"