CVE-2026-102722EPSS p13.7%

CVE-2026-102722CVE-2026-102722

Description

In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.

Scoring

EPSS0.24% probability of exploitation · percentile 13.7% · 2026-10-05T12:00:23Z
Last modified2026-09-29
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.