LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2021-40438

CVE-2021-40438

Apache HTTP Server-Side Request Forgery (SSRF)

CVSS 9 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2021-12-01. Federal remediation due 2021-12-15.
Required action: Apply updates per vendor instructions.

Summary

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS 3.1 breakdown

Base score9 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Resf rocky linuxRedhat enterprise linuxRedhat enterprise linux eusRedhat enterprise linux for arm 64Redhat enterprise linux for arm 64 eusRedhat enterprise linux for ibm z systemsRedhat enterprise linux for ibm z systems eusRedhat enterprise linux for ibm z systems eus s390xRedhat enterprise linux for power big endianRedhat enterprise linux for power little endianRedhat enterprise linux for power little endian eusRedhat enterprise linux for scientific computingRedhat enterprise linux serverRedhat enterprise linux server ausRedhat enterprise linux server for power little endian update services for sap solutionsRedhat enterprise linux server tusRedhat enterprise linux server update services for sap solutionsRedhat enterprise linux update services for sap solutionsRedhat enterprise linux workstationRedhat jboss core services
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-27. Always verify against the vendor advisory before acting.

Scroll to Top