https://seclists.org/oss-sec/2026/q2/842: CVE-2026-44186: Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.67
Frequently Asked Questions
1
What is the severity of CVE-2026-44186?
The severity of CVE-2026-44186 is classified as moderate.
2
What versions of Apache HTTP Server are affected by CVE-2026-44186?
CVE-2026-44186 affects Apache HTTP Server versions 2.4.0 through 2.4.67.
3
What causes CVE-2026-44186?
CVE-2026-44186 is caused by an infinite loop vulnerability in the mod_proxy_ftp module when interacting with an attacker-controlled backend FTP server.
4
How can I mitigate the risk of CVE-2026-44186?
To mitigate the risk of CVE-2026-44186, it is recommended to upgrade to a version of Apache HTTP Server that is not affected by this vulnerability.
5
Is there a workaround for CVE-2026-44186?
Currently, there is no official workaround for CVE-2026-44186 other than upgrading to a patched version.