CVE-2026-63090
HIGHProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
Title source: cnaDescription
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.
References (6)
Core 6
Core References
Release Notes release-notes
Release Notes
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
Patch patch
Patch Commit
https://github.com/proftpd/proftpd/commit/4ee8701bcf425f11b3b2116e634ff3e655d918b1
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/proftpd-mod-sftp-heap-buffer-overflow-via-sftp-packet-reassembly
Release Notes patch
release-notes
v1.3.10rc3 Pre-release Tag
https://github.com/proftpd/proftpd/releases/tag/v1.3.10rc3-3
Release Notes patch
release-notes
v1.3.9c Release Tag
https://github.com/proftpd/proftpd/releases/tag/v1.3.9c
Scores
CVSS v3
8.8
EPSS
0.0046
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-122
Status
published
Products (3)
proftpd/proftpd
1.3.10 rc1 (2 CPE variants)
proftpd/proftpd
< 1.3.9c (2 CPE variants)
proftpd/proftpd
1.3.10rc1 - 1.3.10rc3
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026