CISA KEV · catalog date Dec 1, 2021 · first observed Jul 26, 2026
Evidence dossier
CVE-2021-40438
mod_proxy SSRF
Exploited in the wild (CISA KEV since Dec 1, 2021). NVD reports CVSS 3.1 9.0. EPSS estimates 100.0% exploit likelihood as of Jul 26, 2026.
As of Aug 27, 2026
Normalized restatement
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- State
- PUBLISHED
- Published
- Sep 16, 2021
- Updated
- Aug 6, 2026
- Evidence coverage
- 85%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Apache HTTP Server-Side Request Forgery (SSRF)
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache HTTP Server-Side Request Forgery (SSRF)
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 100th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999970000000
- Source dateSource date omittedFirst observed by CASCAapacheOriginal evidence ↗
Record text: mod_proxy SSRF
Inspect raw assertion
- Field
container- Value
- mod_proxy SSRF
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
FIRST EPSS · score date Jul 26, 2026 · 100th percentile · first observed Jul 27, 2026
NVD · CVSS 3.1 · first observed Aug 6, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
Apache HTTP Server-Side Request Forgery (SSRF)
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache HTTP Server-Side Request Forgery (SSRF)
100% probability · 100th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999970000000
mod_proxy SSRF
Inspect raw assertion
- Field
container- Value
- mod_proxy SSRF
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Applicability
Cited product scope
Grouped from 14 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
43 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Apache HTTP Server 2.4", "versionType": "custom", "lessThanOrEqual": "2.4.48"}]product-9ac1ed1c70311d36a45c72f8dd14128e1f8de18b347393d0fa18e946c202b58bLinked exactInspect raw assertion
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 2.4.48
- Match ID
1691c7ce-5cda-4b9a-854e-3b58c1115526
product-c6ad37339ad83e4d3b31af95b311870c1d8653472a6db5a781ad2a975bb45ed3Linked exactInspect raw assertion
cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2748912-fc54-47f6-8c0c-b96784765b8e
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07b237a9-69a3-4a9c-9da0-4e06bd37ae73
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa6feec2-9f11-4643-8827-749718254fed
product-2ae3bdb0fb063fd01c3676685c6b8c632c29d415f55db11956b722e02856e7d4Linked exactInspect raw assertions
cpe:2.3:o:f5:f5os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 1.1.0; through including 1.1.4
- Match ID
80a2efab-4d06-4254-b2fe-5d1f84bdfd3a
cpe:2.3:o:f5:f5os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 1.2.0; through including 1.2.1
- Match ID
dbacfb6f-d57e-4eca-81bb-9388e64f7df3
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80e516c0-98a4-4ade-b69f-66a772e2baaa
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a930e247-0b43-43cb-98ff-6ce7b8189835
product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bfLinked exactInspect raw assertion
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5c2089ee-5d7f-47ec-8ea5-0f69790564c4
product-9deb406337bc2f1c6e94e78e4893f051c692e3d9f7ac7174d6252a164a205bbfLinked exactInspect raw assertion
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1fe996b1-6951-4f85-aa58-b99a379d2163
product-2bbc3c87cbaeb11c12dc34b42c7207fa49eea659fc62aa79757b51047802fc97Linked exactInspect raw assertion
cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8adff451-740f-4dba-bd23-3881945d3e40
product-1a32432af689ea0bc3ff9b90c5029f0506d7000b62ea7a504dc98cbf6d36ddf5Linked exactInspect raw assertion
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b095cc03-7077-4a58-ab25-cc5380cdce5a
product-bfccd54e33671fad7b63685c4bf72cdbd53aad278e2a851c4928fef18206adceLinked exactInspect raw assertions
cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad04bee5-e9a8-4584-a68c-0195ce9c402c
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfc79b17-e9d2-44d5-93ed-2f959e7a3d43
product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09Linked exactInspect raw assertions
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f69b9a5-f21b-4904-9f27-95c0f7a628e3
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b9c9bc66-fa5f-4774-9bda-7ab88e2839c4
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82ea4ba7-c38b-4af3-8914-9e3d089ebdd4
product-ac2307c300daf5a65e6864085c447fb1b1cd8d175fccb832252024ced9fcae47Linked exactInspect raw assertion
cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9da11710-9ea8-49b4-8fd1-3aee442f6adc
product-422d347a32dcb530963062c00279c72253e55aefd10d03ceb330a7dbb1b6c5d3Linked exactInspect raw assertion
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d3e503fb-6279-4d4a-91d8-e237ecf9d2b0
product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cff558-3c47-480d-a2f0-babf26042943
product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
142ad0dd-4cf3-4d74-9442-459ce3347e3a
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cff558-3c47-480d-a2f0-babf26042943
product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0e3f09b5-569f-4c58-9fca-3c0953d107b5
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
92bc9265-6959-4d37-be5e-8c45e98992f8
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
62c31522-0a17-4025-b269-855c7f4b45c2
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
831f0f47-3565-4763-b16f-c87b1ff2035e
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c3741b8-851f-475d-b428-523f4f722350
product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3f797f2e-00e6-4d03-a94e-524227529a0a
product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3efbeee7-8bc5-4f4e-8efa-42a6743152bb
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
83981111-e13a-4a88-80fd-f63d7ccaa47f
product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2148300c-ecbd-4ed5-a164-79629859dd43
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87c21fe1-ea5c-498f-9c6c-d05f91a88217
product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
280d547b-f204-4848-9262-a103176b740c
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
83364f5c-57f4-4d57-b54f-540cac1d7753
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8c9bd9ae-46fc-4609-8d99-a3cfe91d58d1
product-7ce3aa9d5ccf00dbe1d056c7af556a21690db3daba9e04563b174c187d08062dLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus_s390x:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
725566b6-4319-489e-9a69-9e36ed2950df
product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1cdcff34-6f1d-45a1-be37-6a0e17b04801
product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47811209-5ce5-4375-8391-b0a7f6a0e420
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b4a684c7-88fd-43c4-9bdb-ae337fcbd0ab
product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5c80db2-4a78-4ec9-b2a8-1e4d902c4834
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
729c515e-1dd3-466d-a50b-afe058ffc94a
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8eb6f417-25d0-4a28-b7ba-d21929eaa9e9
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
983533dd-3970-4a37-9a9c-582bd48aa1e5
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a49abd84-6755-4894-ad4e-49aad39933c2
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HAV:N/AC:M/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.