
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-57229 is an SMTP/MIME parsing vulnerability in Suricata that allows detection bypass via incomplete state reset. Affecting Suricata versions 8.0.0 through 8.0.5, the flaw enables crafted SMTP MIME messages to cause outer MIME part encoding or filename state to carry into an inner message, allowing attackers to evade network detections. It was published on July 21, 2026, and patched in Suricata 8.0.6. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is an improper initialization issue (CWE-665) in Suricata's SMTP MIME parser, where the parser state is not fully reset when processing Content-Type: message/rfc822 encapsulation. This allows encoding or filename state from an outer MIME part to bleed into an inner message during parsing. An unauthenticated, remote attacker can exploit this by sending a specially crafted SMTP MIME message over the network, requiring no privileges or user interaction. The fix is tracked in the Suricata commit c0215c7e175b0000ef8450928dd1f3453c48379b (GitHub Advisory, GitHub Commit).
Successful exploitation allows an attacker to evade Suricata-based network detections that rely on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. The primary impact is an integrity loss — specifically, the bypass of security monitoring and detection rules — with no direct confidentiality or availability impact. This could allow malicious email attachments or URLs to pass through Suricata-protected network segments undetected (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-57229. The CVE was reserved and the advisory published on July 21, 2026, with credit given to researcher Changcheng Wu (@Clouditera). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no EPSS score data is currently available (GitHub Advisory).
Content-Type: message/rfc822 encapsulation where the outer MIME part contains encoding or filename state (e.g., a specific Content-Transfer-Encoding or Content-Disposition: filename) that should not apply to the inner message.message/rfc822 part that would normally be detected by Suricata rules targeting file.data, file.name, or extracted URLs.Content-Type: message/rfc822 MIME structures with unusual or mismatched Content-Transfer-Encoding or Content-Disposition headers in outer versus inner parts.message/rfc822 encapsulation; absence of expected alerts for known-malicious file names or URLs in such messages.file.data or file.name rule alerts for SMTP traffic that contains nested MIME structures, particularly when compared against mail server logs showing attachment delivery.Upgrade to Suricata 8.0.6 or later, which contains the fix for the incomplete MIME state reset. The official advisory confirms no workarounds are available for this vulnerability. Organizations running Suricata 8.0.0 through 8.0.5 with SMTP MIME decoding enabled should prioritize this upgrade (GitHub Advisory, Suricata Release).
The vulnerability was credited to researcher Changcheng Wu (@Clouditera), and the advisory was published by Suricata maintainer jasonish on GitHub. The Suricata project released versions 8.0.6 and 7.0.17 simultaneously to address multiple issues, with the release announced on the official Suricata forum and blog. OpenSUSE and other Linux distributions issued security update announcements for their Suricata packages following the release (Suricata Forum, Suricata Release, OpenSUSE Advisory).
Verfügbarkeit von Korrekturen in den wichtigsten Linux-Distributionen und deren Versionen.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"