CVE-2026-8328

MEDIUMCVSS 5.9/10EPSS 0.46%

Last modified

CVE-2026-8328 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). EPSS estimates a 0.46% chance of exploitation in the next 30 days.

Description

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Python Software FoundationCPython< 3.10.21; >= 3.11.0, < 3.11.16; >= 3.12.0, < 3.12.14; >= 3.13.0, < 3.13.14; >= 3.14.0, < 3.14.6; >= 3.15.0a1, < 3.15.0b2

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-8328?
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
How severe is CVE-2026-8328?
CVE-2026-8328 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.46% probability of exploitation in the next 30 days.
How do I fix CVE-2026-8328?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-8328?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST