CVE-2021-40438 (matched: apache http server)

  • Saturday, 8th August, 2026
  • 04:04am

A security flaw has been found in the Apache HTTP Server software that runs most websites on our hosting platform. The issue impacts Apache HTTP Server version 2.4.48 and all older versions, and is triggered when a bad actor sends a specially crafted web request to a site. This tricks the server's built-in request forwarding feature into sending that request to an external server selected by the attacker, rather than the intended destination for your website.

Since this flaw lets attackers control where requests from your site are sent, it could lead to

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back