LOWVulnerability
CVE-2026-8328
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
Properties
- last_source
- FIRST EPSS
- epss_score
- 0.00683
- cve_id
- CVE-2026-8328
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- retrieved_at
- 2026-09-25T11:11:37+00:00
- published_at
- 2026-05-13T21:16:50.167
- last_modified
- 2026-08-13T01:16:55.950
- epss_percentile
- 0.50419
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Server-Side Request Forgery (SSRF)
Explore deeper with Ninja Signal's threat intelligence graph