In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:34:41.445Z

Reserved: 2026-09-29T16:15:17.733Z

Link: CVE-2026-102722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T18:17:11.693

Modified: 2026-09-29T18:17:11.693

Link: CVE-2026-102722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses