ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated… (CVE-2026-63090)
ProFTPD versions before 1.3.9c and 1.3.10rc3 contain a heap-based buffer overflow vulnerability in the mod_sftp module. This flaw allows authenticated low-privilege attackers to execute arbitrary code by sending specially crafted SFTP packet fragments that exceed the 16 KB reassembly buffer. The vulnerability involves corrupting memory structures and redirecting function calls to execute system commands. No patch information is currently provided.
AI Analysis
Technical Summary
The vulnerability in ProFTPD's mod_sftp module arises from improper handling of oversized SFTP packet fragments in the fxp.c component. Authenticated attackers with low privileges can send crafted fragments exceeding the 16 KB buffer, triggering a heap-based buffer overflow. This overflow corrupts pool freelist metadata and overwrites the root_fs global pointer to reference a fake filesystem structure. Consequently, the pr_fsio_stat() function can be redirected to system() via a crafted RENAME request, enabling arbitrary code execution. This affects versions before 1.3.9c and 1.3.10rc3. No official patch or remediation details are currently available.
Potential Impact
Successful exploitation allows authenticated low-privilege attackers to achieve arbitrary code execution on the affected system. This can lead to full compromise of the ProFTPD server, potentially allowing attackers to execute commands with the privileges of the ProFTPD process.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the mod_sftp service to trusted users only and monitor for suspicious activity related to SFTP packet handling.
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated… (CVE-2026-63090)
Description
ProFTPD versions before 1.3.9c and 1.3.10rc3 contain a heap-based buffer overflow vulnerability in the mod_sftp module. This flaw allows authenticated low-privilege attackers to execute arbitrary code by sending specially crafted SFTP packet fragments that exceed the 16 KB reassembly buffer. The vulnerability involves corrupting memory structures and redirecting function calls to execute system commands. No patch information is currently provided.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ProFTPD's mod_sftp module arises from improper handling of oversized SFTP packet fragments in the fxp.c component. Authenticated attackers with low privileges can send crafted fragments exceeding the 16 KB buffer, triggering a heap-based buffer overflow. This overflow corrupts pool freelist metadata and overwrites the root_fs global pointer to reference a fake filesystem structure. Consequently, the pr_fsio_stat() function can be redirected to system() via a crafted RENAME request, enabling arbitrary code execution. This affects versions before 1.3.9c and 1.3.10rc3. No official patch or remediation details are currently available.
Potential Impact
Successful exploitation allows authenticated low-privilege attackers to achieve arbitrary code execution on the affected system. This can lead to full compromise of the ProFTPD server, potentially allowing attackers to execute commands with the privileges of the ProFTPD process.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the mod_sftp service to trusted users only and monitor for suspicious activity related to SFTP packet handling.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wxc2-grp8-f55h
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63090"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a5e7a642a4a8d59899de0b1
Added to database: 07/20/2026, 19:43:32 UTC
Last enriched: 07/20/2026, 20:47:04 UTC
Last updated: 07/21/2026, 06:56:05 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.