CVE Database · CVE-2021-40438
CVSS v3.1
9.0
EPSS
100.00%
Published
Sep 16, 2021
Modified
Oct 27, 2025
CISA Known Exploited Vulnerability
Added: 2021-12-01 · Due: 2021-12-15
Apply updates per vendor instructions.
Public PoC / Exploit (10)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (87)
References (20)
...and 37 more