CVE-2026-28296 Details
Description
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
A command injection vulnerability has been identified in the FTP backend of GVfs (GNOME Virtual File System). This issue arises from improper input validation of file paths, allowing remote attackers to inject arbitrary FTP commands. The vulnerability is exploited by crafting file paths that include carriage return and line feed (CRLF) sequences. These unsanitized sequences can terminate existing FTP commands and introduce new ones, potentially leading to arbitrary code execution or other serious consequences.
Users are advised to avoid connecting to untrusted FTP servers or opening FTP links from unverified sources. Implementing network-level restrictions to limit outbound connections to trusted FTP servers can also help mitigate the risk. If the GVfs FTP backend is not essential, consider removing or disabling it, although this may impact other desktop features that rely on GVfs for FTP access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 26, 2026CISA-ADP
Assessed Feb 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-28296 | [email protected] | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443003 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat GVfs | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | New CVE Received | [email protected] |
Volerion