PT-2026-65836 · Unknown · Xlight Ftp Server

CVE-2026-67191

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xlight FTP Server versions prior to 3.9.5
Description A pre-authentication heap buffer overflow exists when the software processes SSH client identification strings. A logic error in the termination condition of the recv loop uses an incorrect OR operator instead of an AND operator, allowing remote unauthenticated attackers to write data past the end of a heap buffer. This issue affects any SSH or SFTP connection established before authentication.
Recommendations Update Xlight FTP Server to version 3.9.5 or later.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67191

Affected Products

Xlight Ftp Server