Apache HTTP Server-Side Request Forgery (SSRF)
Apache Software Foundation — Apache HTTP Server
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
9.0
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Published
- Sep 16, 2021
- Modified
- Aug 6, 2026
- Added to KEV
- Dec 1, 2021
- Federal patch due
- Dec 15, 2021
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2021-40438, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Kashkovsky/CVE-2021-40438★ 19
Apache forward request CVE
updated Sep 3, 2026
- sixpacksecurity/CVE-2021-40438★ 14
CVE-2021-40438 exploit PoC with Docker setup.
updated Sep 3, 2026
- sergiovks/CVE-2021-40438-Apache-2.4.48-SSRF-exploit★ 10
CVE-2021-40438 Apache <= 2.4.48 SSRF exploit
updated Jul 14, 2026
- xiaojiangxl/CVE-2021-40438★ 5
updated Sep 3, 2026
- BabyTeam1024/CVE-2021-40438★ 2
updated May 19, 2022
- gassara-kys/CVE-2021-40438★ 1
check CVE-2021-40438
updated Feb 1, 2024
- Cappricio-Securities/CVE-2021-40438★ 1
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
updated Nov 3, 2025
- pisut4152/Sigma-Rule-for-CVE-2021-40438-exploitation-attempt★ 1
Sigma-Rule-for-CVE-2021-40438-Attack-Attemp
updated Dec 3, 2021
References
- cert-portal.siemens.com
- httpd.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.debian.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- security.gentoo.org
- security.netapp.com
- tools.cisco.com
- debian.org
- oracle.com
- oracle.com
- tenable.com
- cisa.gov
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2021-40438?
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
How severe is CVE-2021-40438?
CVE-2021-40438 has a CVSS base score of 9.0 out of 10 (CVSS 3.1).
Is CVE-2021-40438 actively exploited in the wild?
Yes. CVE-2021-40438 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Dec 1, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2021-40438?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2021-40438?
Yes - a public Nuclei template referencing CVE-2021-40438 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2021-40438?
CVE-2021-40438 is classified under CWE-918 (CWE-918 Server Side Request Forgery (SSRF)).
Cross-checked against
Impactr finds and proves whether CVE-2021-40438 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist