CVE-2026-44186: Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
Last updated 20 July 2026
Other sources
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the modproxyftp module in Apache HTTP Server with an attacker controlled backend FTP server.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server (mod_proxy_ftp)to a version that resolves this vulnerability.Fixed in 2.4.68 - Compensating control
If upgrading is not immediately possible, restrict or isolate access to any FTP backend systems used by mod_proxy_ftp, so an attacker cannot provide an attacker-controlled/unreachable FTP backend.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44186?
CVE-2026-44186 has a risk rating of 26, indicating a critical vulnerability.
How do I fix CVE-2026-44186?
To address CVE-2026-44186, upgrade your Apache HTTP Server to version 2.4.68 or later.
What impact does CVE-2026-44186 have on my system?
CVE-2026-44186 can lead to an infinite loop when interacting with an attacker-controlled backend FTP server, causing service disruption.
Which versions of Apache HTTP Server are affected by CVE-2026-44186?
CVE-2026-44186 affects Apache HTTP Server versions from 2.4.0 to 2.4.67.
Is there a workaround for CVE-2026-44186?
There is no officially recommended workaround for CVE-2026-44186; upgrading to a fixed version is necessary.