Unrated severityNVD Advisory· Published Oct 1, 2026
CVE-2026-63045
CVE-2026-63045
Description
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.4.68
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.