{"id":"AZL-86913","summary":"CVE-2026-8328 affecting package python3 for versions less than 3.12.9-13","details":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","modified":"2026-08-31T05:26:27Z","published":"2026-05-13T21:16:50Z","upstream":["CVE-2026-8328"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328"}],"affected":[{"package":{"name":"python3","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.12.9-13"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86913.json"}}],"schema_version":"1.9.0"}