← Browse

CVE-2021-40438

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
9.0 CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
100.0%
100.0th percentile
CISA KEV
Listed
Added 2021-12-01 · patch by 2021-12-15
Weakness / dates
CWE-918
Published 2021-09-16 · modified 2026-08-06

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected

apache broadcom debian f5 fedoraproject netapp oracle redhat resf siemens tenable

References

Official: NVD · CVE.org