Improper Validation in Apache HTTP Server Allows Arbitrary Third-Party Connections
CVE-2026-63045

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-63045?

The Apache HTTP Server has a vulnerability relating to the improper validation of the FTP PASV reply address in mod_proxy_ftp. This flaw allows for forward proxy configurations to be exploited, wherein an untrusted FTP server can send a maliciously crafted PASV response. This results in the proxy being tricked into initiating a data connection to an arbitrary third-party host, potentially leading to unauthorized data access or manipulation. Users are encouraged to update to version 2.4.69 to mitigate this risk.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhen Kong
4ra1n, pyn3rd and unam4
Charles Vosburgh
sungbyeongchan
Daradigu / RELAUNCH DEPT.
.