A vulnerability was found in ProFTPD Project ProFTPD up to 1.3.9. It has been rated as problematic. Affected is the function fxp_packet_read of the component Mod Sftp. The manipulation of the argument packet_len leads to heap-based buffer overflow.

This vulnerability is listed as CVE-2026-53994. The attack may be initiated remotely. There is no available exploit.