CVE-2026-29170 is a vulnerability in Apache HTTP Server
Published on June 8, 2026
Apache HTTP Server: mod_proxy_ftp XSS
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Timeline
Report received
fixed in 2.4.x by r1934982 92 days later.
2.4.68 released 4 days later.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-29170 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-29170
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Before and including 2.4.67 is affected.