Vulnerability CVE-2026-44331: Information

Description

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability.

Severity: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: May 5, 2026
Modified: June 17, 2026
Error type identifier: CWE-89

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
proftpdsisyphus1.3.9-alt3.b1.3.9-alt4.cALT-PU-2026-10555-1424495Fixed
proftpdsisyphus_riscv641.3.9-alt3.b1.3.9-alt4.cALT-PU-2026-10672-1-Fixed
proftpdsisyphus_loongarch641.3.9-alt3.b1.3.9-alt4.cALT-PU-2026-10695-1-Fixed

References to Advisories, Solutions, and Tools