CVE-2026-29170
published 2026-06-08CVE-2026-29170: A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.50%
39.7th percentile
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | <= 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_ubuntu9.8CRITICAL
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation
vendor_redhat·2026-06-08·CVSS 6.1
CVE-2026-29170 [MEDIUM] CWE-79 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation
httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A flaw was found in Apache HTTP Server, specifically within the `mod_proxy_ftp` module. This cross-site scripting (XSS) vulnerability occurs during the generation of HTML directory lists when the server is configured to list FTP directory contents via either a forward or reverse proxy. An attacker could exploit this by injecting malicious scripts into web pages, which could lead to information dis
VulDB
Apache HTTP Server up to 2.4.67 mod_proxy_ftp cross site scripting (EUVD-2026-35087)
vuldb·2026-06-09·CVSS 6.1
CVE-2026-29170 [MEDIUM] Apache HTTP Server up to 2.4.67 mod_proxy_ftp cross site scripting (EUVD-2026-35087)
A vulnerability was found in Apache HTTP Server up to 2.4.67 and classified as problematic. Impacted is an unknown function of the component mod_proxy_ftp. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-29170. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse
ghsa_unreviewed·2026-06-08
CVE-2026-29170 [MEDIUM] CWE-79 A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-29170 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation [fedora-all]
bugzilla·2026-06-12·CVSS 6.1
CVE-2026-29170 [MEDIUM] CVE-2026-29170 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation [fedora-all]
CVE-2026-29170 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-29170 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation
bugzilla·2026-06-08·CVSS 6.1
CVE-2026-29170 [MEDIUM] CVE-2026-29170 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation
CVE-2026-29170 httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
2026-06-08
Published