apache http-server CVE-2026-63045 is a vulnerability in Apache HTTP Server
Published on October 1, 2026

Apache HTTP Server: mod_proxy_ftp PASV address handling
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Vendor Advisory NVD

Timeline

Report received

fixed in 2.4.x by r1938674 86 days later.

2.4.69 released

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-63045 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-63045

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: