Skip to main content
MEDIUM

CVE-2026-63091

CVSS v3

6.5

MEDIUM

EPSS Score

0.3 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process

Technical details

CVSS v3 Vector
3.1
Published
2026-07-20
Last Modified
2026-07-20

Frequently asked questions

What is CVE-2026-63091?

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process

Is CVE-2026-63091 actively exploited?

Active exploitation of CVE-2026-63091 has not been confirmed. The EPSS score is 0.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-63091?

CVE-2026-63091 has a CVSS v3 base score of 6.5 (MEDIUM severity), with vector string 3.1.

Is CVE-2026-63091 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key