A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html |
|
History
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache Software Foundation
Apache Software Foundation apache Http Server |
|
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Http Server |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | |
| Title | Apache HTTP Server: mod_proxy_ftp XSS | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-08T15:10:09.141Z
Reserved: 2026-03-04T12:16:21.060Z
Link: CVE-2026-29170
No data.
Status : Received
Published: 2026-06-08T16:16:38.093
Modified: 2026-06-08T16:16:38.093
Link: CVE-2026-29170
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:30:06Z