Input validation error in Apache HTTP Server - CVE-2026-63045
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the proxy to open a data connection to an arbitrary third-party host.
The vulnerability exists due to improper input validation in mod_proxy_ftp PASV reply address handling when processing a crafted PASV response from an untrusted FTP server. A remote attacker can send a crafted PASV response to cause the proxy to open a data connection to an arbitrary third-party host.
The issue is limited to forward proxy configurations.