CVE-2026-8328: Python Software Foundation Cpython
Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
Affected products
- Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.14 (fixed in 3.13.14); from 3.14.0, before 3.14.6 (fixed in 3.14.6); from 3.15.0a1, before 3.15.0b2 (fixed in 3.15.0b2)
Published 2026-05-13. Last modified 2026-08-13.