Repository navigation
ftplib should not use the host from the PASV response #87451
Description
Activity
Last year, curl had a security update for CVE-2020-8284. more info, see https://hackerone.com/reports/1040166
The problem is ftp client trust the host from PASV response by default, A malicious server can trick ftp client into connecting
back to a given IP address and port. This may make ftp client scan ports and extract service banner from private newwork.After test and read ftplib module(
), I found ftplib has the same problem.Line 346 in 6329893
host, port = self.makepasv() - added3.9 (EOL)end of lifeend of lifestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
on Feb 21, 2021 Any response here? If you need more information let me know.
Indeed, the
hoston that line there should just be ignored with the IP address of the original data connection used in its place.Your https://hackerone.com/reports/1040166 link provides plenty of information and likes to prior art mitigations other ftp clients including Firefox and Chrome well over a decade ago.
- added3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life
on Mar 13, 2021 40 remaining items
- added 5 commits that reference this issue
on May 13, 2026 - added 4 commits that reference this issue
on Sep 18, 2026
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs