boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-70637HIGH
hfiref0x LightFTP — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   N   H    8.2   .0023   13.7     —
AFFECTED
  Product   Versions     Fixed
  LightFTP  unspecified  —
TIMELINE
  Aug 4   Reserved by VulnCheck
  Aug 6   Published (CNA: VulnCheck)
  Aug 13  EXPLOIT PUBLISHED — CVE-2026-70637 (hfiref0x LightFTP). Public exploit reference added.
CWE-820 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received

Description

LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 4, 2026ReservedReserved by VulnCheck
August 6, 2026PublishedPublished (CNA: VulnCheck)
August 13, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-70637 (hfiref0x LightFTP). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
hfiref0xLightFTP

Weaknesses

CWE-820

References (2)

Related

Authoritative record: CVE-2026-70637 at cve.org

Vendors: hfiref0x

Weaknesses: CWE-820

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-70637 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.