Cross-site scripting in Apache HTTP Server - CVE-2026-29170
Published: June 8, 2026
Apache HTTP Server
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in mod_proxy_ftp HTML directory list generation when listing FTP directory contents via forward or reverse proxy configuration. A remote attacker can control FTP directory listing content to execute arbitrary script in a victim's browser.
The issue occurs during FTP directory listing generation.