PT-2026-47324 · Apache+4 · Apache Http Server+4

CVE-2026-44186

·

Published

2026-04-27

·

Updated

2026-08-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.67
Description The mod proxy ftp module contains a loop with an unreachable exit condition, leading to an infinite loop when interacting with an attacker-controlled backend FTP server.
Recommendations Upgrade to version 2.4.68.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:41906
ALSA-2026:42828
AZL-89741
BDU:2026-09750
BIT-APACHE-2026-44186
CVE-2026-44186
ECHO-16E4-FFAC-D93D
OESA-2026-2744
OESA-2026-2745
OESA-2026-2746
OESA-2026-2747
OPENSUSE-SU-2026:21235-1
RHSA-2026:25042
RHSA-2026:34109
RHSA-2026:42828
SUSE-SU-2026:22564-1
SUSE-SU-2026:2686-1
SUSE-SU-2026:2717-1
SUSE-SU-2026:2735-1
SUSE-SU-2026:2759-1
USN-8516-1
USN-8571-1

Affected Products

Apache Http Server
Linuxmint
Red Os
Rocky Linux
Ubuntu