CyberRota
Live Feed
Back to database

CVE-2021-40438

CRITICAL · CVSS 9 EPSS 100.00% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published: 2021-09-16 · Last synced: 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Known

Added to KEV: 2021-12-01

Required action: Apply updates per vendor instructions.

CVE
CVE-2021-40438
Severity
CRITICAL
CVSS
9
EPSS
100.00%
Apache

Original NVD Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.