VYPR
Unrated severityCISA KEVNVD Advisory· Published Sep 16, 2021· Updated Oct 21, 2025

mod_proxy SSRF

CVE-2021-40438

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected products

1
  • Apache Software Foundation/Apache HTTP Serverv5
    Range: Apache HTTP Server 2.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

19

News mentions

0

No linked articles in our index yet.