CVE-2026-28295
published 2026-02-26CVE-2026-28295: A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive…
PriorityP425medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.19%
8.5th percentile
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gvfs | < gvfs 1.46.2-2+deb11u1 (bullseye) | gvfs 1.46.2-2+deb11u1 (bullseye) |
| gnome | gvfs | >= 0 < 1.46.2-2+deb11u1 | 1.46.2-2+deb11u1 |
| gnome | gvfs | >= 0 < 1.59.90-1 | 1.59.90-1 |
| gnome | gvfs | >= 0 < 1.48.2-0ubuntu1.1 | 1.48.2-0ubuntu1.1 |
| gnome | gvfs | >= 0 < 1.54.4-0ubuntu1~24.04.2 | 1.54.4-0ubuntu1~24.04.2 |
| gnome | gvfs | >= 0 < 1.57.2-2ubuntu5.1 | 1.57.2-2ubuntu5.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GVfs vulnerabilities
vendor_ubuntu·2026-03-23·CVSS 4.3
CVE-2026-28296 [MEDIUM] GVfs vulnerabilities
Title: GVfs vulnerabilities
Summary: Several security issues were fixed in GVfs.
It was discovered that the GVfs FTP backend incorrectly handled IP
addresses and ports returned by passive mode responses. A malicious remote
server could possibly use this issue to help scan for open ports.
(CVE-2026-28295)
It was discovered that the GVfs FTP backend incorrectly handled crafted
file paths. A remote attacker could use this issue to terminate or inject
arbitrary FTP commands, or possibly execute arbitrary code.
(CVE-2026-28296)
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses
vendor_redhat·2026-02-26·CVSS 4.3
CVE-2026-28295 [MEDIUM] CWE-918 gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses
gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible fro
Debian
CVE-2026-28295: gvfs - A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit thi...
vendor_debian·2026·CVSS 4.3
CVE-2026-28295 [MEDIUM] CVE-2026-28295: gvfs - A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit thi...
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1.46.2-2+deb11u1)
forky: resolved (fixed in 1.59.90-1)
sid: resolved (fixed in 1.59.90-1)
trixie: open
OSV
gvfs vulnerabilities
osv·2026-03-23·CVSS 4.3
CVE-2026-28295 [MEDIUM] gvfs vulnerabilities
gvfs vulnerabilities
It was discovered that the GVfs FTP backend incorrectly handled IP
addresses and ports returned by passive mode responses. A malicious remote
server could possibly use this issue to help scan for open ports.
(CVE-2026-28295)
It was discovered that the GVfs FTP backend incorrectly handled crafted
file paths. A remote attacker could use this issue to terminate or inject
arbitrary FTP commands, or possibly execute arbitrary code.
(CVE-2026-28296)
OSV
CVE-2026-28295: A flaw was found in the FTP GVfs backend
osv·2026-02-26·CVSS 4.3
CVE-2026-28295 [MEDIUM] CVE-2026-28295: A flaw was found in the FTP GVfs backend
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
GHSA
GHSA-pp79-4qx3-mf4h: A flaw was found in the FTP GVfs backend
ghsa_unreviewed·2026-02-26
CVE-2026-28295 [MEDIUM] CWE-918 GHSA-pp79-4qx3-mf4h: A flaw was found in the FTP GVfs backend
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28295 gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses
bugzilla·2026-02-26·CVSS 4.3
CVE-2026-28295 [MEDIUM] CVE-2026-28295 gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses
CVE-2026-28295 gvfs: GVfs FTP backend: Information disclosure via untrusted PASV responses
The FTP GVfs backend in daemon/gvfsftptask.c:868-907 unconditionally trusts the IP address and port returned in PASV responses from FTP servers. When handling passive mode data transfers, the code parses the server's PASV reply and directly constructs a GInetSocketAddress without validating that the advertised IP matches the control connection or restricting private/internal addresses. The client then connects to this arbitrary endpoint via g_vfs_ftp_connection_open_data_connection().
This allows an attacker (the malicious server) to probe the existence of open ports accessible to the client.
Wiz
CVE-2026-28295 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-28295 [MEDIUM] CVE-2026-28295 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28295 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
Source : NVD
## 4.3
Score
Published February 26, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.6
Exploitation Probability (EPSS) N/A
Affected packages and libra
2026-02-26
Published