Vulnerability Intelligence Report
FileZilla 3.40.0 Denial of Service via Local Search
CVE-2019-25683
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.
No Active Exploit Signals
CVSS Base Score
6.9
MEDIUM
EPSS Probability:0.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-532 ↗Insertion of Sensitive Information into Log File
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Filezilla-Project | FileZilla | 3.40.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.173%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-04-05T15:16:49 |
| Published | 2026-04-05T20:45:32 |
| Patch Date | 2019-02-20 |
| Last Updated | 2026-04-06T18:12:56 |
Community Chatter & Buzz