Zurück zur CVE-Übersicht
CVE-2026-8328
NONERisk Signal Score0/100 — NIEDRIG
EPSS-Score
0%
Exploit-Wahrscheinlichkeit (30 Tage)
Beschreibung
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
Referenzen
- https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca0...
- https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f...
- https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be0076...
- https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1...
- https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf...
- https://github.com/python/cpython/issues/87451
- https://github.com/python/cpython/pull/149648
- https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BA...