Feed/CVE-2021-40438
CVE-2021-40438CRITICALCVSS 9.0CISA KEV: Actively Exploited

Apache HTTP Server-Side Request Forgery (SSRF)

Published Dec 1, 2021·Updated Aug 6, 2026

NVD Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Public Exploits & PoCs11 found

[POC] CVE-2021-40438 — CVE-2021-40438

CVE-2021-40438 exploit PoC with Docker setup.

9

[POC] CVE-2021-40438 — CVE-2021-40438

Apache forward request CVE

2

[POC] CVE-2021-40438 — Sigma-Rule-for-CVE-2021-40438-exploitation-attempt

Sigma-Rule-for-CVE-2021-40438-Attack-Attemp

1

[POC] CVE-2021-40438 — check-point-gateways-rce

Check Point Security Gateways RCE via CVE-2021-40438

1

[POC] CVE-2021-40438 — check-point-gateways-rce

Check Point Security Gateways RCE via CVE-2021-40438

[POC] CVE-2021-40438 — CVE-2021-40438

check CVE-2021-40438

[POC] CVE-2021-40438 — apache-cve-poc

Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48.

[POC] CVE-2021-40438 — CVE-2021-40438_Docker

An Application Server Docker build for CVE-2021-40438

[POC] CVE-2021-40438 — CVE-2021-40438

Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery

[POC] CVE-2021-40438 — CVE-2021-40438-Apache-2.4.48-SSRF-exploit

CVE-2021-40438 Apache <= 2.4.48 SSRF exploit

PoC: CVE-2021-40438_Docker_2

Second one for web vulnerability (FYP Project, for own use only)

Community Discussion

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free