CVE-2026-8328
EUVD-2026-3017713.05.2026, 21:16
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.13.14 | CNA |
| python | cpython | 3.14.0 ≤ 𝑥 < 3.14.6 | CNA |
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pypy3 |
| ||||||||||||
| python2.7 |
| ||||||||||||
| python3.11 |
| ||||||||||||
| python3.13 |
| ||||||||||||
| python3.14 |
| ||||||||||||
| python3.9 |
|
Vulnerability Media Exposure
References