{"schema_version":"1.7.5","id":"PSF-0000-CVE-2026-8328","published":"2026-05-13T20:14:33.751Z","modified":"2026-06-05T11:26:19.433754675Z","aliases":["BIT-libpython-2026-8328","BIT-python-2026-8328","BIT-python-min-2026-8328","CVE-2026-8328","PSF-2026-24"],"details":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python/cpython","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-0000-CVE-2026-8328.json"}}],"references":[{"type":"REPORT","url":"https://github.com/python/cpython/issues/87451"},{"type":"WEB","url":"https://github.com/python/cpython/pull/149648"},{"type":"ADVISORY","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"}],"database_specific":{"cwe_ids":[]}}