December 1, 2021 · Applied Cybernetics Group
CVE-2021-40438 — Apache Apache
known ransomware use
Apache HTTP Server-Side Request Forgery (SSRF)
- Added to KEV
2021-12-01- Federal due date
2021-12-15- Vendor
- Apache
- Product
- Apache
- EPSS
- 100.0th percentile (score 1.000, as of
2026-09-16) - NVD CVSS v3.1
- 9 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-40438
CISA short description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Required action
Apply updates per vendor instructions.
NVD description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.