A security issue has been identified in Apache HTTP Server, the common software used to run and manage websites. This flaw affects Apache HTTP Server version 2.4.48 and all earlier released versions of the software.
The issue impacts the server's mod_proxy feature, which passes incoming visitor requests to backend systems that power the site. If a malicious actor sends a specially crafted web request to a site running an affected version, they could trick this feature into forwarding the request to a third-party server of the attacker's choosing, instead of the intended backend system.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438