Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2021-40438

Apache HTTP Server-Side Request Forgery (SSRF)

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

cat cve-2021-40438.json
Vendor
Apache
Product
Apache
CVSS
9.0
EPSS (exploit probability)
100.0%
Status
kevransomware use
CISA patch-by (BOD 22-01)
Published

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2021-12-01. Required action per CISA: Apply updates per vendor instructions. Due date: 2021-12-15.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.