Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-67191— Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser

CVSS 9.8 · Critical EPSS 0.58% · P44

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
XlightXlight FTP Server< 3.9.5affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-67191

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser
Source: CVE Program / CVE List V5
Vulnerability Description
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP connection before authentication occurs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5
Vulnerability Title
Xlight FTP Server 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
xlight ftp server是xlight ftp server个人开发者的一款轻量级FTP服务器软件。 Xlight FTP Server 3.9.5之前版本存在缓冲区错误漏洞,该漏洞源于预认证堆缓冲区溢出,由于recv循环终止条件逻辑错误(使用了错误的OR运算符),导致远程未认证攻击者通过发送畸形SSH客户端标识字符串,可写入堆缓冲区之外。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
XlightXlight FTP Server 0 ~ 3.9.5 -

II. Public POCs for CVE-2026-67191

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67191

登录查看更多情报信息。

Vendor Pages for CVE-2026-67191 (1)

Other References for CVE-2026-67191 (1)

Same Patch Batch · Xlight · 2026-07-29 · 3 CVEs total

CVE-2026-671928.1 HIGHXlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher
CVE-2026-671935.3 MEDIUMXlight FTP Server < 3.9.5 Information Disclosure via USER Command

IV. Related Vulnerabilities

V. Comments for CVE-2026-67191

No comments yet


Leave a comment