A security flaw has been found in older versions of the Apache HTTP Server, a widely used tool that routes visitor requests to websites. The issue affects Apache HTTP Server 2.4.48 and all earlier versions. The flaw is triggered by a specially crafted web request sent to a site running the affected software. When triggered, it tricks the server's request forwarding function into sending the request to a remote server chosen by the sender, rather than the intended server your site uses to deliver content.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438