A security flaw has been identified in Apache HTTP Server, affecting all versions up to and including 2.4.48. The issue impacts servers that use the mod_proxy feature, a tool designed to forward incoming web requests to backend servers that power your website. When a specially crafted web request is sent to an affected server, the flaw can trick mod_proxy into forwarding that request to an origin server selected by the person sending the request, rather than the intended backend server. This could allow unauthorized users to send requests to systems they should not be able to access through your website, or misuse your server's proxy functionality for unintended, potentially harmful purposes.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438