CVE-2026-63045 concerns inadequate validation of the address in an FTP PASV response by Apache HTTP Server's mod_proxy_ftp module. The advisory was published on October 1, 2026 and rates the issue low severity.
According to the advisory, versions 2.4.0 through 2.4.68 are affected on all platforms. In forward proxy configurations, an untrusted FTP server can send a crafted PASV response that induces the proxy to open a data connection to an arbitrary third-party host.
Administrators can check whether they use mod_proxy_ftp and whether a forward proxy is exposed to untrusted FTP servers. Compare the installed version with the affected range and consult Apache's official channels for current remediation guidance; the available text does not specify a fixed version.
To confirm the scope and recommendations, consult the original oss-sec advisory and Apache's official notices, checking the date, versions, and any updates. If using an AI tool to study or apply the material, avoid submitting configurations, credentials, or identifiable internal data.