Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-63090: ProFTPD mod_sftp Module Allows Code Execution
CVE-2026-63090
CVE-2026-63090
Summary
ProFTPD's SFTP module has a bug that can be exploited by authorized users to execute malicious code. This is a concern because it could allow attackers to take control of your server. To protect your system, update ProFTPD to the latest version, specifically 1.3.9c or 1.3.10rc3 and later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| proftpd | proftpd | < 1.3.9c |
Original title
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
Original description
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-122
Heap-based Buffer Overflow
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/commit/4ee8701bcf425f11b3b2116e634ff3e655d918...
- https://github.com/proftpd/proftpd/issues/2190
- https://github.com/proftpd/proftpd/releases/tag/v1.3.10rc3-3
- https://github.com/proftpd/proftpd/releases/tag/v1.3.9c
- https://www.vulncheck.com/advisories/proftpd-mod-sftp-heap-buffer-overflow-via-s...
Published: 20 Jul 2026 · Updated: 22 Jul 2026 · First seen: 20 Jul 2026