CVE-2026-44186
published 2026-06-08CVE-2026-44186: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP…
PriorityP347high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.58%
44.4th percentile
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_ubuntu9.8CRITICAL
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 5.3
CVE-2026-34032 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server
vendor_redhat·2026-06-08·CVSS 7.3
CVE-2026-44186 [HIGH] CWE-835 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server
httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in the `mod_proxy_ftp` module of the Apache HTTP Server. A remote attacker, by controlling a backend File Transfer Protocol (FTP) server, can trigger an infinite loop. This vulnerability, categorized as a Loop with Unreachable Exit Condition, leads to a Denial of Service (DoS) for the affected server.
Statement: A loop with an unreachable exit condition flaw was found in the mod_pr
GHSA
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
ghsa_unreviewed·2026-06-08
CVE-2026-44186 [HIGH] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
VulDB
Apache HTTP Server up to 2.4.67 mod_proxy_ftp proxy_ftp_handler infinite loop (EUVD-2026-35088)
vuldb·2026-06-08
CVE-2026-44186 [LOW] Apache HTTP Server up to 2.4.67 mod_proxy_ftp proxy_ftp_handler infinite loop (EUVD-2026-35088)
A vulnerability described as problematic has been identified in Apache HTTP Server up to 2.4.67. This affects the function proxy_ftp_handler of the component mod_proxy_ftp. Such manipulation leads to infinite loop.
This vulnerability is documented as CVE-2026-44186. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server [fedora-all]
bugzilla·2026-07-08·CVSS 7.3
CVE-2026-44186 [HIGH] CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server [fedora-all]
CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Bugzilla
CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server
bugzilla·2026-06-08·CVSS 7.3
CVE-2026-44186 [HIGH] CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server
CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
2026-06-08
Published