CVE-2026-44186

Apache HTTP Server vulnerabilities

Beschreibung

Schwachstelle durch Endlos-Schleife ('Infinite Loop') im mod_proxy_ftp-Modul des Apache HTTP Servers mit einem vom Angreifer kontrollierten Backend FTP-Server. Dieses Problem betrifft undefinierte Versionen von 2.4.0 bis einschließlich 2.4.67. Es wird empfohlen, auf die Version 2.4.68 zu aktualisieren, die das Problem behebt.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.5
Quelle: nvd-v3
46.0 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-20 19:03 UTC
CWE-835

Weakness-Klassen (CWE)

  • CWE-835Base

    Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-23 07:10 UTC· nvd@nist.gov
    • Translation: Title: Apache HTTP Server, Description: Bucle con condición de salida inalcanzable ('Bucle infinito') vulnerabilidad en el módulo mod_proxy_ftp en el Servidor HTTP Apache con un servidor FTP de backend controlado por el atacante. Este problema afecta a indefinido: desde 2.4.0 hasta 2.4.67. Se recomienda a los usuarios actualizar a la versión 2.4.68, que corrige el problema.
  2. Initial Analysis2026-06-11 04:01 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* versions from (including) 2.4.0 up to (excluding) 2.4.68
    • Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/06/08/13 Types: Mailing List, Third Party Advisory
    • Reference Type: Apache Software Foundation: https://httpd.apache.org/security/vulnerabilities_24.html Types: Vendor Advisory
  3. CVE Modified2026-06-08 23:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/06/08/13
  4. New CVE Received2026-06-08 16:16 UTC· security@apache.org
    • Description: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
    • CWE: CWE-835
    • Reference: https://httpd.apache.org/security/vulnerabilities_24.html

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.55

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-44186
Apache HTTP Server vulnerabilities — CVE-2026-44186 | NEOSEC Intel