Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-63090 Details

Description

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-122Heap-based Buffer Overflow[email protected]

Affected Products

ProductVersions
proftpd proftpd
< 1.3.9c
1.3.10 rc1
1.3.10 rc2

CPE

  • cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*
  • cpe:2.3:a:proftpd:proftpd:1.3.10:rc1:*:*:*:*:*:*
  • cpe:2.3:a:proftpd:proftpd:1.3.10:rc2:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-63090
NVD Published Date:
Jul 20, 2026
NVD Last Modified:
Jul 30, 2026
Source:
[email protected]
CVE-2026-63090 Details - Not Deferred