CVE-2026-67192

HIGH

Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher

Title source: cna
STIX 2.1

Description

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achieve remote code execution before any authentication occurs.

References (2)

Core 2
Core References
Release Notes release-notes
Changelog
https://www.xlightftpd.com/whatsnew.htm

Scores

CVSS v3 8.1
EPSS 0.0062
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
Xlight/Xlight FTP Server < 3.9.5
Published Jul 29, 2026
Tracked Since Jul 29, 2026