Skip to main content
MEDIUM

CVE-2026-63091

CVSS v3

6.5

MEDIUM

EPSS Score

0.5 %

exploit probability, as of 2026-10-06

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process

Technical details

Published
2026-07-20
Last Modified
2026-07-20

Frequently asked questions

What is CVE-2026-63091?

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process

Is CVE-2026-63091 actively exploited?

Active exploitation of CVE-2026-63091 has not been confirmed. Its EPSS score was 0.5% on 2026-10-06, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-63091?

CVE-2026-63091 has a CVSS v3 base score of 6.5 (MEDIUM severity).

Is CVE-2026-63091 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key