CVE-2021-40438

All FrameworksApache HTTPDCWE-918CVE-2021-40438

CVE-2021-40438

State: PUBLISHED · Published: 2021-09-16 · Updated: 2025-10-21 · Assigner: apache
Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/40xxx/CVE-2021-40438.json