CVE-2021-40438 (matched: apache http server)

  • Sunday, 9th August, 2026
  • 04:03am

A security flaw has been identified in Apache HTTP Server, the common software that powers a large number of websites. This issue impacts version 2.4.48 and all older releases of the software.

The flaw is triggered when someone sends a specially crafted request to a site running the affected version. It impacts the server's mod_proxy feature, which passes visitor requests to the backend servers that host your site's content and services. When exploited, this feature can be tricked into forwarding the request to a server chosen by the person sending the request, instead of your site's intended backend.

This could allow an attacker to send malicious traffic to other systems via your server's proxy connection, or access resources on unintended servers that they would not normally be able to reach. The flaw does not affect sites running Apache HTTP Server version 2.4.49 or newer.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back