In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltabfetchclientscb() in contrib/modwrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability.
{
"cwe_ids": [
"CWE-89"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44331.json",
"cna_assigner": "mitre"
}"2026-07-27T09:24:25Z"
[
{
"signature_type": "Line",
"target": {
"file": "contrib/mod_wrap2_sql.c"
},
"deprecated": false,
"source": "https://github.com/proftpd/proftpd/commit/766622456440fbca33abd7927c523673a11d1ed1",
"id": "CVE-2026-44331-57249226",
"signature_version": "v1",
"digest": {
"line_hashes": [
"188482706554823101810217099371113475442",
"68337044015778869399813398219364202197",
"334365133394600081695344133386138485036",
"84965816477830368718499911502919309885",
"257689760143191922139795645690342910699",
"279078725103272610705499487142617442562",
"200755676198081997654057562277869569473",
"185160440974126000080114331374655820147",
"125458845817003328104264753665928310783",
"263248335264980344081424844571976700176",
"236080155514241972172298194553298885942",
"46161859100360679407753404889689615657",
"82567606603689545712045968230310458907",
"171101706885532581099216327660532567177",
"310242041935806729107316771436680950336"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "contrib/mod_wrap2_sql.c",
"function": "sqltab_fetch_clients_cb"
},
"deprecated": false,
"source": "https://github.com/proftpd/proftpd/commit/766622456440fbca33abd7927c523673a11d1ed1",
"id": "CVE-2026-44331-f10affcc",
"signature_version": "v1",
"digest": {
"function_hash": "223779140751552999123681835048876320623",
"length": 2108.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44331.json"