CVE-2021-40438 (matched: apache http server)

  • Thursday, 6th August, 2026
  • 10:06am

A security flaw has been identified in Apache HTTP Server, the open-source web server software that powers the vast majority of websites hosted on our platform. This issue allows a remote attacker to send a specially crafted web request that tricks the server's proxy functionality into forwarding the request to an arbitrary third-party server of the attacker's choosing, rather than the intended origin server for your website. The flaw affects Apache HTTP Server version 2.4.48 and all earlier released versions.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back