CVE-2026-28296
published 2026-02-26CVE-2026-28296: A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths…
PriorityP427medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.36%
28.6th percentile
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gvfs | < gvfs 1.46.2-2+deb11u1 (bullseye) | gvfs 1.46.2-2+deb11u1 (bullseye) |
| gnome | gvfs | >= 0 < 1.46.2-2+deb11u1 | 1.46.2-2+deb11u1 |
| gnome | gvfs | >= 0 < 1.59.90-1 | 1.59.90-1 |
| gnome | gvfs | >= 0 < 1.48.2-0ubuntu1.1 | 1.48.2-0ubuntu1.1 |
| gnome | gvfs | >= 0 < 1.54.4-0ubuntu1~24.04.2 | 1.54.4-0ubuntu1~24.04.2 |
| gnome | gvfs | >= 0 < 1.57.2-2ubuntu5.1 | 1.57.2-2ubuntu5.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GVfs vulnerabilities
vendor_ubuntu·2026-03-23·CVSS 4.3
CVE-2026-28296 [MEDIUM] GVfs vulnerabilities
Title: GVfs vulnerabilities
Summary: Several security issues were fixed in GVfs.
It was discovered that the GVfs FTP backend incorrectly handled IP
addresses and ports returned by passive mode responses. A malicious remote
server could possibly use this issue to help scan for open ports.
(CVE-2026-28295)
It was discovered that the GVfs FTP backend incorrectly handled crafted
file paths. A remote attacker could use this issue to terminate or inject
arbitrary FTP commands, or possibly execute arbitrary code.
(CVE-2026-28296)
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths
vendor_redhat·2026-02-26·CVSS 4.3
CVE-2026-28296 [MEDIUM] CWE-93 gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths
gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbi
Debian
CVE-2026-28296: gvfs - A flaw was found in the FTP GVfs backend. A remote attacker could exploit this i...
vendor_debian·2026·CVSS 4.3
CVE-2026-28296 [MEDIUM] CVE-2026-28296: gvfs - A flaw was found in the FTP GVfs backend. A remote attacker could exploit this i...
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1.46.2-2+deb11u1)
forky: resolved (fixed in 1.59.90-1)
sid: resolved (fixed in 1.59.90-1)
trixie: open
OSV
gvfs vulnerabilities
osv·2026-03-23·CVSS 4.3
CVE-2026-28295 [MEDIUM] gvfs vulnerabilities
gvfs vulnerabilities
It was discovered that the GVfs FTP backend incorrectly handled IP
addresses and ports returned by passive mode responses. A malicious remote
server could possibly use this issue to help scan for open ports.
(CVE-2026-28295)
It was discovered that the GVfs FTP backend incorrectly handled crafted
file paths. A remote attacker could use this issue to terminate or inject
arbitrary FTP commands, or possibly execute arbitrary code.
(CVE-2026-28296)
GHSA
GHSA-r8j5-pj3m-qhpv: A flaw was found in the FTP GVfs backend
ghsa_unreviewed·2026-02-26
CVE-2026-28296 [MEDIUM] CWE-93 GHSA-r8j5-pj3m-qhpv: A flaw was found in the FTP GVfs backend
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
OSV
CVE-2026-28296: A flaw was found in the FTP GVfs backend
osv·2026-02-26·CVSS 4.3
CVE-2026-28296 [MEDIUM] CVE-2026-28296: A flaw was found in the FTP GVfs backend
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28296 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-28296 [MEDIUM] CVE-2026-28296 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28296 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
Source : NVD
## 4.3
Score
Published February 26, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.2
Exploitation Probability (EPSS) 0.1
Bugzilla
CVE-2026-28296 gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths
bugzilla·2026-02-26·CVSS 4.3
CVE-2026-28296 [MEDIUM] CVE-2026-28296 gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths
CVE-2026-28296 gvfs: FTP GVfs backend: Arbitrary FTP command injection via CRLF sequences in file paths
The FTP GVfs backend fails to sanitize CRLF sequences in user supplied file paths before constructing FTP protocol commands. When g_vfs_ftp_file_new_from_gvfs() creates a file object in daemon/gvfsftpfile.c:77-87, it copies the path without validation. This unsanitized path flows through g_vfs_ftp_file_get_ftp_path() into command format strings like "RETR %s" at daemon/gvfsbackendftp.c:883. In daemon/gvfsftptask.c:661, g_string_append_vprintf() includes the malicious path directly into the command buffer, allowing embedded \r\n sequences to terminate the intended command and inject arbitrary FTP commands.
2026-02-26
Published