Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44186

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

A flaw was found in the mod_proxy_ftp module of the Apache HTTP Server. A remote attacker, by controlling a backend File Transfer Protocol (FTP) server, can trigger an infinite loop. This vulnerability, categorized as a Loop with Unreachable Exit Condition, leads to a Denial of Service (DoS) for the affected server.

Отчет

A loop with an unreachable exit condition flaw was found in the mod_proxy_ftp module of the Apache HTTP Server. A remote attacker could exploit this vulnerability by tricking the server into connecting to a malicious or compromised backend FTP server, causing the proxy_ftp_handler component to enter an infinite loop. This results in CPU exhaustion and a denial of service (DoS) condition on the affected system.

Меры по смягчению последствий

To mitigate this issue, you can disable the mod_proxy_ftp module if your environment does not require it.

Step 1: Disable the Module

Open your Apache HTTP Server configuration file (commonly located at /etc/httpd/conf.modules.d/00-proxy.conf or /etc/httpd/conf/httpd.conf) and comment out or remove the following line:

# LoadModule proxy_ftp_module modules/mod_proxy_ftp.so

Step 2: Restart the Service

Restart the httpd service to apply the configuration changes:

systemctl restart httpd

Note: Disabling this module may impact applications or services that rely on Apache's FTP proxy functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:4282821.07.2026
Red Hat Enterprise Linux 9httpdFixedRHSA-2026:4190620.07.2026
Red Hat Hardened Imageshttpd-main-2.4.68-1.hum1FixedRHSA-2026:2504210.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2486402httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server

EPSS

Процентиль: 44%
0.00583
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 месяцев назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.3
nvd
около 2 месяцев назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
около 2 месяцев назад

Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp

CVSS3: 7.3
debian
около 2 месяцев назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...

CVSS3: 7.3
github
около 2 месяцев назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

EPSS

Процентиль: 44%
0.00583
Низкий

7.3 High

CVSS3