
CVE-2026-8328: CPython: FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address https://www.openwall.com/lists/oss-security/2026/05/14/1
Post summary
A new CPython vulnerability (CVE‑2026‑8328) is disclosed, where the FTP PASV command enables SSRF because the client trusts the server‑supplied host address and ignores the actual peer address.


