High severity7.3NVD Advisory· Published Jun 8, 2026· Updated Jun 11, 2026
CVE-2026-44186
CVE-2026-44186
Description
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: >=2.4.0 <=2.4.67
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/08/13nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
News mentions
3- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026
- Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow FlawsCyber Security News · Jun 9, 2026
- Apache HTTP Server: 11 Vulnerabilities Disclosed, Including DoS and Memory Corruption FlawsVypr Intelligence · Jun 8, 2026