VYPR
Unrated severityNVD Advisory· Published Sep 15, 2012· Updated Apr 29, 2026

CVE-2012-4001

CVE-2012-4001

Description

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.

Affected products

2
  • cpe:2.3:a:google:mod_pagespeed:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:google:mod_pagespeed:*:*:*:*:*:*:*:*range: <=0.10.22.4
    • cpe:2.3:a:google:mod_pagespeed:0.10.19.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.