A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html |
|
History
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache Software Foundation
Apache Software Foundation apache Http Server |
|
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Http Server |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | |
| Title | Apache HTTP Server: mod_proxy_ftp XSS | |
| Weaknesses | CWE-79 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-08T18:18:07.968Z
Reserved: 2026-03-04T12:16:21.060Z
Link: CVE-2026-29170
No data.
Status : Received
Published: 2026-06-08T16:16:38.093
Modified: 2026-06-08T16:16:38.093
Link: CVE-2026-29170
No data.
OpenCVE Enrichment
Updated: 2026-06-08T17:30:06Z
Weaknesses