LOWVulnerability

CVE-2026-8328

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.

Properties

last_source
FIRST EPSS
epss_score
0.00683
cve_id
CVE-2026-8328
signal_observed_at
2026-09-11T17:55:57+00:00
retrieved_at
2026-09-25T11:11:37+00:00
published_at
2026-05-13T21:16:50.167
last_modified
2026-08-13T01:16:55.950
epss_percentile
0.50419

Related Entities (3)

ENRICHED_BY (1)

→[Source]FIRST EPSS

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph