CVE-2026-63045
Apache HTTP Server: mod_proxy_ftp PASV address handling
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
| CWE | CWE-284 |
| Vendor | apache software foundation |
| Product | apache http server |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache http server
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache http server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache HTTP Server
2.4.0 โค 2.4.68
References
Credits
Zhen Kong 4ra1n, pyn3rd and unam4 Charles Vosburgh sungbyeongchan Daradigu / RELAUNCH DEPT.