CVE-2026-102722EPSS p13.7%
CVE-2026-102722CVE-2026-102722
Description
In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
Scoring
| EPSS | 0.24% probability of exploitation · percentile 13.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |