CVE-2021-40438 (matched: apache http server)

  • Monday, 3rd August, 2026
  • 16:04pm

A security vulnerability has been identified in the Apache HTTP Server, a common tool used to run and manage websites, that impacts version 2.4.48 and all earlier releases of the software.

The flaw is triggered when a specially crafted web request is sent to a server running the affected Apache version. This request can trick the server's built-in proxy feature, which passes traffic between connected servers, into forwarding the request to a server selected by the sender of the malicious request, instead of the intended backend server that hosts your site's content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back