CyberRota Analysis
AI analysis pending.
CISA KEV Details
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Known
Added to KEV: 2021-12-01
Required action: Apply updates per vendor instructions.
CVE
CVE-2021-40438
Severity
CRITICAL
CVSS
9
EPSS
100.00%
Apache
Original NVD Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.