Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP connection before authentication occurs.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xlightftpd
Xlightftpd xlight Ftp Server |
|
| Vendors & Products |
Xlightftpd
Xlightftpd xlight Ftp Server |
Wed, 29 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP connection before authentication occurs. | |
| Title | Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-29T16:32:49.768Z
Reserved: 2026-07-28T16:06:49.773Z
Link: CVE-2026-67191
Updated: 2026-07-29T16:32:22.855Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T15:15:03Z