Zeek is a widely deployed network analysis framework used for traffic inspection and protocol parsing, with its vulnerability footprint centered on a single core product. The recurring issues stem from HTTP request interpretation inconsistencies and null-pointer dereferences, reflecting the complexity of parsing network protocols at scale. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zeek over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-60109HIGH Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-60108HIGH Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2021-41732HIGH An issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ZEEK HTTP based security analysis. NOTE: the vendor's positi | Sep 29, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-12175HIGH In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka KRB) protocol parser leads to DoS because a case-type index i | Jul 17, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zeek.
Media articles that mention a CVE ID that affects a product developed by Zeek — matched by CVE ID, not by vendor name.