CVE-2026-8328Disclosure

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 105-1305-1405-15
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-131
Patch1
2026-05-141
Disclosure1
2026-05-151
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-8328: CPython: FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address https://www.openwall.com/lists/oss-security/2026/05/14/1

    Post summary

    A new CPython vulnerability (CVE‑2026‑8328) is disclosed, where the FTP PASV command enables SSRF because the client trusts the server‑supplied host address and ignores the actual peer address.

    00020226
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8328 Unpatched PASV Host Address Validation in Python ftplib ftpcp() Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8328

    Post summary

    The entry announces CVE-2026-8328, describing a missing PASV host address validation in Python's ftplib ftpcp() function, without providing PoC, exploit code, or patch information.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-8328 The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with t… https://www.cve.org/CVERecord?id=CVE-2026-8328

    Post summary

    The post highlights that CVE-2026-8328 stems from an unfinished update to ftpcp() after CVE-2021-4189 was patched, noting that makepasv() has been fixed while ftpcp() remains unchanged.

    00000137
    57.5K followersView on X

Explore more