A vulnerability was found in ProFTPD Project ProFTPD up to 1.3.9. It has been rated as problematic. Affected is the function
fxp_packet_read of the component Mod Sftp. The manipulation of the argument packet_len leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-53994. The attack may be initiated remotely. There is no available exploit.