apache http-server CVE-2026-29170 is a vulnerability in Apache HTTP Server
Published on June 8, 2026

Apache HTTP Server: mod_proxy_ftp XSS
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Vendor Advisory NVD

Timeline

Report received

fixed in 2.4.x by r1934982 92 days later.

2.4.68 released 4 days later.

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2026-29170 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2026-29170

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: