Suricata smtp/mime: incomplete state reset allows detection bypass
Summary
| CVE | CVE-2026-57229 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-18 21:17:01 UTC |
| Updated | 2026-09-18 21:17:01 UTC |
| Description | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.004120000 probability, percentile 0.351870000 (date 2026-09-20)
Problem Types: CWE-665 | CWE-665 CWE-665: Improper Initialization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/OISF/suricata/commit/c0215c7e175b0000ef8450928dd1f3453c48379b | [email protected] | github.com | |
| github.com/OISF/suricata/commit/4985eb9daea2f765b6ef59a58fa02e5c71c0a77c | [email protected] | github.com | |
| github.com/OISF/suricata/releases/tag/suricata-8.0.6 | [email protected] | github.com | |
| redmine.openinfosecfoundation.org/issues/8649 | [email protected] | redmine.openinfosecfoundation.org | |
| github.com/OISF/suricata/security/advisories/GHSA-ph5p-pm8r-m355 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.