CVE-2021-4189

Python vulnerabilities

mediumEPSS 3.2%

Description

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

Metrics

Severity
medium
no public PoC known
5.3
Source: nvd-v3
87.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-06 11:48 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    ubuntu / python2.7bionic

  • linux

    ubuntu / python2.7focal

  • linux

    ubuntu / python2.7jammy

  • linux

    ubuntu / python2.7trusty

  • linux

    ubuntu / python2.7xenial

  • linux

    ubuntu / python3.10jammy

  • linux

    ubuntu / python3.11jammy

  • linux

    ubuntu / python3.12noble

  • linux

    ubuntu / python3.14resolute

  • linux

    ubuntu / python3.4trusty

  • linux

    ubuntu / python3.5trusty

  • linux

    ubuntu / python3.5xenial

  • linux

    ubuntu / python3.6bionic

  • linux

    ubuntu / python3.7bionic

  • linux

    ubuntu / python3.8bionic

  • linux

    ubuntu / python3.8focal

  • linux

    ubuntu / python3.9focal

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • bitnami

    python-min3.6.0

  • bitnami

    python-min3.7.0

  • bitnami

    python-min3.8.0

  • bitnami

    python-min3.9.0

  • python

    python3.14.0 – 3.14.4

  • python

    python3.13.13

  • python

    python

  • python-markdown

    markdown

References & sources

Linked CVEs

IDCVE-2021-4189