CVE-2026-63045 is a vulnerability in Apache HTTP Server
Published on October 1, 2026
Apache HTTP Server: mod_proxy_ftp PASV address handling
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Timeline
Report received
fixed in 2.4.x by r1938674 86 days later.
2.4.69 released
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-63045 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-63045
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Version 2.4.0, <= 2.4.68 is affected.