LOWVulnerability
CVE-2026-8328
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
Properties
- cve_id
- CVE-2026-8328
- published_at
- 2026-05-13T21:16:50.167
- last_modified
- 2026-08-13T01:16:55.950
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Server-Side Request Forgery (SSRF)
Explore deeper with Ninja Signal's threat intelligence graph