[CVE-2026-8328] FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
May 13, 2026
8:15 p.m.
There is a MEDIUM severity vulnerability affecting CPython.
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport().
Please see the linked CVE ID for the latest information on affected versions:
95
Age (days ago)
95
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson