CVE-2021-40438 (matched: apache http server)

  • Saturday, 1st August, 2026
  • 10:06am

A security flaw has been identified in the Apache HTTP Server, a common tool used to run websites. The issue impacts a component called mod_proxy, which routes incoming web requests to the correct backend server that hosts your site’s content. A specially crafted malicious request can trick this component into forwarding the request to a server selected by the attacker, rather than the intended backend for your site.

This vulnerability affects Apache HTTP Server version 2.4.48 and all older releases. If exploited, this could allow an attacker to send requests to unintended backend systems, potentially accessing data or services they are not authorized to reach through your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back