CVE-2021-40438
mod_proxy SSRF
- Published
- Sep 16, 2021
- Updated
- Aug 6, 2026
- Assigning CNA
- apache
- Evidence observed
- Dec 1, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sources
10- CVE-2021-40438Scanner
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
- CVE-2021-40438Exploit
Proof-of-concept exploit for CVE-2021-40438, an Apache HTTP Server mod_proxy vulnerability allowing request forwarding to arbitrary origins, with a scanner to identify vulnerable servers.
SSRF exploit proof-of-concept for CVE-2021-40438 targeting Apache mod_proxy. Python script with proxy support for controlled testing and educational demonstrations.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.