A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache http Server |
|
| CPEs | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache http Server |
Mon, 08 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache Software Foundation
Apache Software Foundation apache Http Server |
|
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Http Server |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | |
| Title | Apache HTTP Server: mod_proxy_ftp XSS | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2026-06-08T15:10:09.141Z
Updated: 2026-06-08T22:32:22.561Z
Reserved: 2026-03-04T12:16:21.060Z
Link: CVE-2026-29170
Updated: 2026-06-08T22:32:22.561Z
Status : Analyzed
Published: 2026-06-08T16:16:38.093
Modified: 2026-06-09T16:21:31.310
Link: CVE-2026-29170
No data.