Improper Validation in Apache HTTP Server Allows Arbitrary Third-Party Connections
CVE-2026-63045
Currently unrated
What is CVE-2026-63045?
The Apache HTTP Server has a vulnerability relating to the improper validation of the FTP PASV reply address in mod_proxy_ftp. This flaw allows for forward proxy configurations to be exploited, wherein an untrusted FTP server can send a maliciously crafted PASV response. This results in the proxy being tricked into initiating a data connection to an arbitrary third-party host, potentially leading to unauthorized data access or manipulation. Users are encouraged to update to version 2.4.69 to mitigate this risk.
Affected Version(s)
Apache HTTP Server 2.4.0 <= 2.4.68