CVE-2021-40438 (matched: apache http server)

  • Saturday, 1st August, 2026
  • 16:05pm

A security flaw has been identified in Apache HTTP Server, the common web server software used to power many websites, including those hosted on our platform. The issue impacts all versions of Apache HTTP Server 2.4.48 and older.

The flaw exploits the server's mod_proxy feature, which is designed to forward user requests to the correct backend servers to load website content. When an attacker sends a specially crafted web request to an affected server, they can trick the system into forwarding that request to a server of the attacker's choosing, rather than the legitimate, intended backend server.

This misdirection could allow attackers to access restricted content hosted on other servers, redirect your site's visitors to malicious external sites, or cause disruptions to your website's normal operation if the proxy routing is altered.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back