CVE-2021-40438 (matched: apache http server)

  • Sunday, 2nd August, 2026
  • 04:05am

A security flaw has been identified in Apache HTTP Server, the software that runs many websites online. The issue affects a component that passes visitor requests to backend servers: a specially crafted web request can trick this component into sending the request to a server controlled by an attacker, rather than your intended backend server. This vulnerability impacts Apache HTTP Server version 2.4.48 and all earlier versions. If your website runs an affected version of this software, attackers could use this flaw to redirect visitors to malicious or unauthorized sites, or access data that should only be available to your intended backend systems.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back