{"id":"CVE-2021-40438","title":"A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user","summary":"A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-918"],"vendor":"redhat","product":"jboss_core_services","affected":["rocky_linux = 8.0","enterprise_linux = 8.0","enterprise_linux_eus = 8.1","enterprise_linux_eus = 8.2","enterprise_linux_eus = 8.4","enterprise_linux_eus = 8.6","enterprise_linux_eus = 8.8","enterprise_linux_for_arm_64 = 8.0","enterprise_linux_for_arm_64_eus = 8.6","enterprise_linux_for_arm_64_eus = 8.8","enterprise_linux_for_ibm_z_systems = 7.0_s390x","enterprise_linux_for_ibm_z_systems = 8.0","enterprise_linux_for_ibm_z_systems_eus = 8.1","enterprise_linux_for_ibm_z_systems_eus = 8.4","enterprise_linux_for_ibm_z_systems_eus = 8.8","enterprise_linux_for_ibm_z_systems_eus_s390x = 8.2","enterprise_linux_for_power_big_endian = 7.0","enterprise_linux_for_power_little_endian = 7.0","enterprise_linux_for_power_little_endian = 8.0","enterprise_linux_for_power_little_endian_eus = 8.1","enterprise_linux_for_power_little_endian_eus = 8.2","enterprise_linux_for_power_little_endian_eus = 8.4","enterprise_linux_for_power_little_endian_eus = 8.6","enterprise_linux_for_power_little_endian_eus = 8.8","enterprise_linux_for_scientific_computing = 7.0","enterprise_linux_server = 7.0","enterprise_linux_server_aus = 7.2","enterprise_linux_server_aus = 7.3","enterprise_linux_server_aus = 7.4","enterprise_linux_server_aus = 7.6","enterprise_linux_server_aus = 7.7","enterprise_linux_server_aus = 8.2","enterprise_linux_server_aus = 8.4","enterprise_linux_server_aus = 8.6","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.6","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.7","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.1","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.2","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8","enterprise_linux_server_tus = 7.6","enterprise_linux_server_tus = 7.7","enterprise_linux_server_tus = 8.2","enterprise_linux_server_tus = 8.4","enterprise_linux_server_tus = 8.6","enterprise_linux_server_tus = 8.8","enterprise_linux_server_update_services_for_sap_solutions = 7.6","enterprise_linux_server_update_services_for_sap_solutions = 7.7","enterprise_linux_update_services_for_sap_solutions = 8.1","enterprise_linux_update_services_for_sap_solutions = 8.2","enterprise_linux_update_services_for_sap_solutions = 8.4","enterprise_linux_update_services_for_sap_solutions = 8.6","enterprise_linux_update_services_for_sap_solutions = 8.8","enterprise_linux_workstation = 7.0","jboss_core_services = 1.0","software_collections = 1.0","http_server <= 2.4.48","fedora = 34","fedora = 35","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0","cloud_backup","clustered_data_ontap","storagegrid","brocade_fabric_operating_system_firmware","f5os >= 1.1.0, <= 1.1.4","f5os >= 1.2.0, <= 1.2.1","enterprise_manager_ops_center = 12.4.0.0","http_server = 12.2.1.3.0","http_server = 12.2.1.4.0","instantis_enterprisetrack = 17.1","instantis_enterprisetrack = 17.2","instantis_enterprisetrack = 17.3","secure_global_desktop = 5.6","zfs_storage_appliance_kit = 8.8","ruggedcom_nms","sinec_nms < 1.0.3","sinema_remote_connect_server < 3.1","sinema_remote_connect_server = 3.2","sinema_server = 14.0","tenable.sc <= 5.19.1"],"patched":["sinec_nms 1.0.3","sinema_remote_connect_server 3.1"],"published":"2021-09-16","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-40438","references":[{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf","label":"security@apache.org"},{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/","label":"security@apache.org"},{"url":"https://security.gentoo.org/glsa/202208-20","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20211008-0004/","label":"security@apache.org"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-4982","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.tenable.com/security/tns-2021-17","label":"security@apache.org"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202208-20","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20211008-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4982","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.tenable.com/security/tns-2021-17","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40438","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-40438.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-40438"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2005117"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-40438"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40438"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"},{"url":"https://access.redhat.com/errata/RHSA-2021:3856"},{"url":"https://access.redhat.com/errata/RHSA-2021:3746"},{"url":"https://access.redhat.com/errata/RHSA-2021:3754"},{"url":"https://access.redhat.com/errata/RHSA-2021:3837"},{"url":"https://access.redhat.com/errata/RHSA-2021:3836"},{"url":"https://access.redhat.com/errata/RHSA-2021:3816"},{"url":"https://access.redhat.com/errata/RHSA-2021:3745"}],"tags":["nvd","kev","in-the-wild","exploit-available","csaf","vex","red-hat"],"epss":0.99999,"epssPercentile":0.99997,"kev":true,"kevDateAdded":"2021-12-01","kevDueDate":"2021-12-15","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-01T06:11:31.013Z","exploits":{"github":11,"githubRepos":["https://github.com/xiaojiangxl/CVE-2021-40438","https://github.com/sixpacksecurity/CVE-2021-40438","https://github.com/BabyTeam1024/CVE-2021-40438"],"nuclei":["CVE-2021-40438"],"checkedAt":"2026-09-08T15:36:49.467Z"},"exploitAvailable":true,"slug":"CVE-2021-40438","body":"## Overview\n\nA crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.\n\n## Affected\n\n- `rocky_linux = 8.0`\n- `enterprise_linux = 8.0`\n- `enterprise_linux_eus = 8.1`\n- `enterprise_linux_eus = 8.2`\n- `enterprise_linux_eus = 8.4`\n- `enterprise_linux_eus = 8.6`\n- `enterprise_linux_eus = 8.8`\n- `enterprise_linux_for_arm_64 = 8.0`\n- `enterprise_linux_for_arm_64_eus = 8.6`\n- `enterprise_linux_for_arm_64_eus = 8.8`\n- `enterprise_linux_for_ibm_z_systems = 7.0_s390x`\n- `enterprise_linux_for_ibm_z_systems = 8.0`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.1`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.4`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.8`\n- `enterprise_linux_for_ibm_z_systems_eus_s390x = 8.2`\n- `enterprise_linux_for_power_big_endian = 7.0`\n- `enterprise_linux_for_power_little_endian = 7.0`\n- `enterprise_linux_for_power_little_endian = 8.0`\n- `enterprise_linux_for_power_little_endian_eus = 8.1`\n- `enterprise_linux_for_power_little_endian_eus = 8.2`\n- `enterprise_linux_for_power_little_endian_eus = 8.4`\n- `enterprise_linux_for_power_little_endian_eus = 8.6`\n- `enterprise_linux_for_power_little_endian_eus = 8.8`\n- `enterprise_linux_for_scientific_computing = 7.0`\n- `enterprise_linux_server = 7.0`\n- `enterprise_linux_server_aus = 7.2`\n- `enterprise_linux_server_aus = 7.3`\n- `enterprise_linux_server_aus = 7.4`\n- `enterprise_linux_server_aus = 7.6`\n- `enterprise_linux_server_aus = 7.7`\n- `enterprise_linux_server_aus = 8.2`\n- `enterprise_linux_server_aus = 8.4`\n- `enterprise_linux_server_aus = 8.6`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.6`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.7`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.1`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.2`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8`\n- `enterprise_linux_server_tus = 7.6`\n- `enterprise_linux_server_tus = 7.7`\n- `enterprise_linux_server_tus = 8.2`\n- `enterprise_linux_server_tus = 8.4`\n- `enterprise_linux_server_tus = 8.6`\n- `enterprise_linux_server_tus = 8.8`\n- `enterprise_linux_server_update_services_for_sap_solutions = 7.6`\n- `enterprise_linux_server_update_services_for_sap_solutions = 7.7`\n- `enterprise_linux_update_services_for_sap_solutions = 8.1`\n- `enterprise_linux_update_services_for_sap_solutions = 8.2`\n- `enterprise_linux_update_services_for_sap_solutions = 8.4`\n- `enterprise_linux_update_services_for_sap_solutions = 8.6`\n- `enterprise_linux_update_services_for_sap_solutions = 8.8`\n- `enterprise_linux_workstation = 7.0`\n- `jboss_core_services = 1.0`\n- `software_collections = 1.0`\n- `http_server <= 2.4.48`\n- `fedora = 34`\n- `fedora = 35`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `cloud_backup`\n- `clustered_data_ontap`\n- `storagegrid`\n- `brocade_fabric_operating_system_firmware`\n- `f5os >= 1.1.0, <= 1.1.4`\n- `f5os >= 1.2.0, <= 1.2.1`\n- `enterprise_manager_ops_center = 12.4.0.0`\n- `http_server = 12.2.1.3.0`\n- `http_server = 12.2.1.4.0`\n- `instantis_enterprisetrack = 17.1`\n- `instantis_enterprisetrack = 17.2`\n- `instantis_enterprisetrack = 17.3`\n- `secure_global_desktop = 5.6`\n- `zfs_storage_appliance_kit = 8.8`\n- `ruggedcom_nms`\n- `sinec_nms < 1.0.3`\n- `sinema_remote_connect_server < 3.1`\n- `sinema_remote_connect_server = 3.2`\n- `sinema_server = 14.0`\n- `tenable.sc <= 5.19.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sinec_nms 1.0.3`\n- `sinema_remote_connect_server 3.1`\n\n## Vendor advisories\n\n- **RHSA-2021:3856** · Red Hat · fixed in: Red Hat Enterprise Linux Client Optional (v. 7), Red Hat Enterprise Linux ComputeNode Optional (v. 7), Red Hat Enterprise Linux Server AUS (v. 7.2), Red Hat Enterprise Linux Server AUS (v. 7.3), Red Hat Enterprise Linux Server AUS (v. 7.4), Red Hat Enterprise Linux Server AUS (v. 7.6), … · released 2021-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2021:3856)\n- **RHSA-2021:3746** · Red Hat · fixed in: Red Hat JBoss Core Services on RHEL 7 Server, Red Hat JBoss Core Services on RHEL 8 · released 2021-10-07 · [advisory](https://access.redhat.com/errata/RHSA-2021:3746)\n- **RHSA-2021:3754** · Red Hat · fixed in: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7), Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · released 2021-10-11 · [advisory](https://access.redhat.com/errata/RHSA-2021:3754)\n- **RHSA-2021:3837** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 8.1) · released 2021-10-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:3837)\n- **RHSA-2021:3836** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 8.2) · released 2021-10-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:3836)\n- **RHSA-2021:3816** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-10-12 · [advisory](https://access.redhat.com/errata/RHSA-2021:3816)\n- **RHSA-2021:3745** · Red Hat · fixed in: Red Hat JBoss Core Services · released 2021-10-07 · [advisory](https://access.redhat.com/errata/RHSA-2021:3745)","depth":"hadal","depthScore":99,"depthScoreParts":{"impact":49.5,"likelihood":20,"exploitation":25,"ransomware":5},"changes":[{"seq":4538,"id":"CVE-2021-40438","ts":1788887189250,"field":"exploit_available","old":"false","new":"true"},{"seq":3421,"id":"CVE-2021-40438","ts":1788886306541,"field":"exploit_available","old":"true","new":"false"},{"seq":2276,"id":"CVE-2021-40438","ts":1788882976288,"field":"exploit_available","old":"false","new":"true"},{"seq":1305,"id":"CVE-2021-40438","ts":1788882388208,"field":"exploit_available","old":"true","new":"false"},{"seq":419,"id":"CVE-2021-40438","ts":1788881823448,"field":"exploit_available","old":"false","new":"true"}]}