Back

MEDIUM

FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address

Published May 13, 2026

Description

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PSF
Published May 13, 2026
Updated Aug 13, 2026
Reserved May 11, 2026
CISA Vulnrichment
Updated May 14, 2026
NVD
Status Awaiting Analysis
Modified Aug 13, 2026
Red Hat
Severity Important
Public date May 13, 2026