Skip to content
Rota Nacional

Cyber ·

CVE-2026-63045: mod_proxy_ftp risk

An advisory published on October 1, 2026 describes a low-severity flaw in Apache HTTP Server, on all platforms, in versions 2.4.0 through 2.4.68. In certain forward proxy configurations, an untrusted FTP server can direct a data connection to an arbitrary host.

CVE-2026-63045 concerns inadequate validation of the address in an FTP PASV response by Apache HTTP Server's mod_proxy_ftp module. The advisory was published on October 1, 2026 and rates the issue low severity.

According to the advisory, versions 2.4.0 through 2.4.68 are affected on all platforms. In forward proxy configurations, an untrusted FTP server can send a crafted PASV response that induces the proxy to open a data connection to an arbitrary third-party host.

Administrators can check whether they use mod_proxy_ftp and whether a forward proxy is exposed to untrusted FTP servers. Compare the installed version with the affected range and consult Apache's official channels for current remediation guidance; the available text does not specify a fixed version.

To confirm the scope and recommendations, consult the original oss-sec advisory and Apache's official notices, checking the date, versions, and any updates. If using an AI tool to study or apply the material, avoid submitting configurations, credentials, or identifiable internal data.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free