These are all security issues fixed in the lftp-4.9.2-1.7 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "lftp": "4.9.2-1.7" } ] }