Home

Description

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

PUBLISHED Reserved 2026-03-04 | Published 2026-06-08 | Updated 2026-06-08 | Assigner apache

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

Any version
affected

Timeline

2026-03-04:Report received
2026-06-04:fixed in 2.4.x by r1934982
2026-06-08:2.4.68 released

Credits

Pavel Kohout, Aisle Research, Aisle.com finder

References

www.openwall.com/lists/oss-security/2026/06/08/5

httpd.apache.org/security/vulnerabilities_24.html vendor-advisory

cve.org (CVE-2026-29170)

nvd.nist.gov (CVE-2026-29170)

Download JSON