CVE-2026-53994 is a heap-based buffer overflow vulnerability in ProFTPD mod_sftp. An authenticated SFTP user can exploit this vulnerability to cause a denial of service. The vulnerability exists due to an integer underflow and size truncation issue in the fxp_packet_read() function. This issue allows an attacker to submit an oversized SFTP packet length, which can lead to a heap buffer overflow. The vulne [truncated]
CVE-2026-35025 is a high-severity vulnerability in ProFTPD, a popular FTP server software. The vulnerability allows authenticated FTP users to bypass directory access control lists (ACLs) by prefixing paths with /proc/self/root in the RNFR command handler. This enables attackers to perform rename operations on files in DenyAll-protected directories and subsequently retrieve those files. The vulnerability [truncated]