CVE-2026-60108
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/07/2026
Last modified:
14/07/2026
Description
Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT control line. Attackers can exploit the NVT_Analyzer component's lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the Zeek sensor.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zeek:zeek:*:*:*:*:*:*:*:* | 8.0.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



