What is CVE-2026-67191?
Xlight FTP Server versions prior to 3.9.5 contain a pre-authentication heap buffer overflow vulnerability. Remote unauthenticated attackers can exploit this by sending a malformed SSH client identification string to write past the heap buffer boundary. Upgrading to version 3.9.5 or later is strongly recommended.
Azərbaycanca: Xlight FTP Server-in 3.9.5-dən əvvəlki versiyalarında autentifikasiyadan əvvəl heap buffer overflow zəifliyi aşkarlanıb. Bu, uzaqdan autentifikasiya olunmamış hücumçulara SSH client identifikasiya sətrini manipulyasiya edərək yaddaşda yazma imkanı verir. Serveri 3.9.5 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Xlight
FAQ1
What type of vulnerability was discovered in Xlight FTP Server before authentication?
A pre-authentication heap buffer overflow vulnerability was discovered in Xlight FTP Server versions prior to 3.9.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.