PT-2026-103934 · Apache · Apache Http Server

·

CVE-2026-63045

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Improper validation of FTP PASV reply address in mod proxy ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63045

Affected Products

Apache Http Server