CVE-2026-67191
Xlight FTP Server versions before 3.9.5 contain a heap buffer overflow that can be triggered by sending a specially crafted SSH client identification string. The flaw allows attackers to write beyond a heap buffer before authentication, potentially enabling arbitrary code execution. The vulnerability is critical because it can be exploited remotely without any credentials.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Xlight FTP Server versions earlier than 3.9.5, when accessed via SSH or SFTP before authentication.
Real-world impact
An attacker could send a malformed SSH client identification string to an Xlight FTP Server and overwrite memory, which may allow them to run arbitrary code on the server or crash it.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability is exploitable remotely (no authentication required), has a high impact on confidentiality, integrity, and availability, and can lead to full system compromise.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources