mod_proxy SSRF
Summary
| CVE | CVE-2021-40438 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-16 15:15:07 UTC |
| Updated | 2026-08-01 05:16:54 UTC |
| Description | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Risk And Classification
Primary CVSS: v3.1 9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.999990000 probability, percentile 0.999970000 (date 2026-08-01)
CISA KEV: Listed on 2021-12-01; due 2021-12-15; ransomware use Known
Problem Types: CWE-918 | CWE-918 CWE-918 Server Side Request Forgery (SSRF)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | Apache |
|---|---|
| Product | Apache |
| Name | Apache HTTP Server-Side Request Forgery (SSRF) |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2021-40438 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache HTTP Server | affected Apache HTTP Server 2.4 2.4.48 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| [SECURITY] [DLA 2776-1] apache2 security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| [R1] Stand-alone Security Patch Available for Tenable.sc versions 5.16.0 to 5.19.1: Patch 202110.1 - Security Advisory | Tenable® | af854a3a-2127-422b-91ae-364da2661108 | www.tenable.com | Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4982-1 apache2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Third Party Advisory |
| September 2021 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Apache HTTPD: Multiple Vulnerabilities (GLSA 202208-20) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| [SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Release Notes |
| Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | af854a3a-2127-422b-91ae-364da2661108 | httpd.apache.org | Release Notes, Vendor Advisory |
| Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021 | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Broken Link, Third Party Advisory |
| lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fb... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a5... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| [SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Release Notes |
| cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf | af854a3a-2127-422b-91ae-364da2661108 | cert-portal.siemens.com | Third Party Advisory |
| lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List |
| [SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| [SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
CNA: The issue was discovered by the Apache HTTP security team while analysing CVE-2021-36160 (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2021-09-16T00:00:00.000Z | 2.4.49 released |
| ADP | 2021-12-01T00:00:00.000Z | CVE-2021-40438 added to CISA KEV |
Legacy QID Mappings
- 150461 Apache HTTP Server mod_proxy Server Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
- 159418 Oracle Enterprise Linux Security Update for httpd:2.4 (ELSA-2021-3816)
- 159419 Oracle Enterprise Linux Security Update for httpd (ELSA-2021-3856)
- 178815 Debian Security Update for apache2 (DLA 2776-1)
- 178819 Debian Security Update for apache2 (DSA 4982-1)
- 182834 Debian Security Update for apache2 (CVE-2021-40438)
- 198516 Ubuntu Security Notification for Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities (USN-5090-1)
- 239667 Red Hat Update for httpd24-httpd (RHSA-2021:3754)
- 239668 Red Hat Update for Red Hat JBoss Core Services Apache Hypertext Transfer Protocol Server (HTTP Server) 2.4.37 SP9 (RHSA-2021:3746)
- 239671 Red Hat Update for httpd:2.4 (RHSA-2021:3816)
- 239681 Red Hat Update for httpd (RHSA-2021:3856)
- 239686 Red Hat Update for httpd:2.4 (RHSA-2021:3837)
- 239687 Red Hat Update for httpd:2.4 (RHSA-2021:3836)
- 239871 Red Hat Update for httpd:2.4 (RHSA-2021:4537)
- 257120 CentOS Security Update for httpd (CESA-2021:3856)
- 281910 Fedora Security Update for Hypertext Transfer Protocol Daemon (HTTPd) (FEDORA-2021-dce7e7738e)
- 352857 Amazon Linux Security Advisory for httpd24: ALAS-2021-1543
- 352858 Amazon Linux Security Advisory for httpd: ALAS2-2021-1716
- 375988 Apache Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities
- 376041 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493841)
- 376256 Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2022)
- 376381 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493845,6493841)
- 376961 NetApp Clustered Data Open Network Technology for Appliance Products (ONTAP) Disclosure of Sensitive Information Vulnerability (NTAP-20211008-0004)
- 377000 Alibaba Cloud Linux Security Update for httpd (ALINUX2-SA-2021:0059)
- 377101 Alibaba Cloud Linux Security Update for httpd:2.4 (ALINUX3-SA-2021:0074)
- 378336 Zimbra Collaboration Suite (ZCS) Multiple Vulnerabilities
- 38856 Cisco TelePresence Video Communication Server (VCS) Apache Hypertext Transfer Protocol Server (HTTP Server) Vulnerability (cisco-sa-apache-httpd-2.4.49-VWL69sWQ)
- 500022 Alpine Linux Security Update for apache2
- 503713 Alpine Linux Security Update for apache2
- 591221 Siemens SINEC NMS and SINEMA Server Multiple Vulnerabilities (SSA-685781 V1.1)
- 671157 EulerOS Security Update for httpd (EulerOS-SA-2021-2803)
- 671166 EulerOS Security Update for httpd (EulerOS-SA-2021-2915)
- 671168 EulerOS Security Update for httpd (EulerOS-SA-2021-2923)
- 671190 EulerOS Security Update for httpd (EulerOS-SA-2021-2931)
- 671266 EulerOS Security Update for httpd (EulerOS-SA-2022-1167)
- 671293 EulerOS Security Update for httpd (EulerOS-SA-2022-1206)
- 671333 EulerOS Security Update for httpd (EulerOS-SA-2022-1225)
- 690025 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (882a38f9-17dd-11ec-b335-d4c9ef517024)
- 710595 Gentoo Linux Apache HTTPD Multiple Vulnerabilities (GLSA 202208-20)
- 730209 Apache Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities
- 731099 Hewlett Packard Enterprise (HPE) OneView Multiple Vulnerabilities (HPESBGN04586)
- 751198 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2021:3299-1)
- 751216 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2021:3335-1)
- 751279 OpenSUSE Security Update for apache2 (openSUSE-SU-2021:3522-1)
- 751314 OpenSUSE Security Update for apache2 (openSUSE-SU-2021:1438-1)
- 87468 Apache Hypertext Transfer Protocol (HTTP) Server mod_proxy Server-Side Request Forgery (SSRF) Vulnerability
- 87470 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493841)
- 900331 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (5489)
- 901829 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (6487-1)
- 940297 AlmaLinux Security Update for httpd:2.4 (ALSA-2021:3816)
- 960440 Rocky Linux Security Update for httpd:2.4 (RLSA-2021:3816)