A security flaw has been identified in Apache HTTP Server, a common piece of software used to power a large number of websites. This flaw is officially tracked as CVE-2021-40438.
The issue impacts servers running Apache's mod_proxy feature, a tool designed to pass web requests between different servers. If a remote user sends a specially crafted request to an affected server, the flaw can trick the system into forwarding that request to an origin server selected by the remote user, rather than the intended server you set up for your site.
This flaw affects all versions of Apache HTTP Server 2.4.48 and earlier.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438