A security flaw has been identified in Apache HTTP Server, the open-source web server software that powers the vast majority of websites hosted on our platform. This issue allows a remote attacker to send a specially crafted web request that tricks the server's proxy functionality into forwarding the request to an arbitrary third-party server of the attacker's choosing, rather than the intended origin server for your website. The flaw affects Apache HTTP Server version 2.4.48 and all earlier released versions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438