CVE-2021-40438

CRITICAL KEV RANSOMWARE NUCLEI LAB

Apache HTTP Server <2.4.48 - SSRF

Title source: llm

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Exploits (12)

nomisec WORKING POC 16 stars
by Kashkovsky · infoleak
https://github.com/Kashkovsky/CVE-2021-40438
nomisec WORKING POC 12 stars
by sixpacksecurity · infoleak
https://github.com/sixpacksecurity/CVE-2021-40438
nomisec WORKING POC 9 stars
by sergiovks · infoleak
https://github.com/sergiovks/CVE-2021-40438-Apache-2.4.48-SSRF-exploit
nomisec WORKING POC 4 stars
by xiaojiangxl · poc
https://github.com/xiaojiangxl/CVE-2021-40438
github WORKING POC 3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Apache/(SSRF) CVE-2021-40438.md
nomisec STUB 2 stars
by BabyTeam1024 · poc
https://github.com/BabyTeam1024/CVE-2021-40438
nomisec SCANNER 1 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2021-40438
nomisec WORKING POC 1 stars
by gassara-kys · poc
https://github.com/gassara-kys/CVE-2021-40438
nomisec SCANNER 1 stars
by pisut4152 · poc
https://github.com/pisut4152/Sigma-Rule-for-CVE-2021-40438-exploitation-attempt
nomisec WORKING POC
by n0m-d · infoleak
https://github.com/n0m-d/CVE-2021-40438-POC
nomisec WORKING POC
by yakir2b · remote
https://github.com/yakir2b/check-point-gateways-rce
nomisec STUB
by ericmann · poc
https://github.com/ericmann/apache-cve-poc

Nuclei Templates (1)

Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
CRITICALVERIFIEDby pdteam
Shodan: cpe:"cpe:2.3:a:apache:http_server" || apache 2.4.49

References (20)

Scores

CVSS v3 9.0
EPSS 0.9443
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2021-12-01
VulnCheck KEV 2021-12-01
InTheWild.io 2021-11-24
ENISA EUVD EUVD-2021-27615
Ransomware Use Confirmed
CWE
CWE-918
Status published
Products (50)
apache/http_server < 2.4.48
broadcom/brocade_fabric_operating_system_firmware
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
f5/f5os 1.1.0 - 1.1.4
fedoraproject/fedora 34
fedoraproject/fedora 35
netapp/cloud_backup
netapp/clustered_data_ontap
... and 40 more
Published Sep 16, 2021
KEV Added Dec 01, 2021
Tracked Since Feb 18, 2026