Vulnerability record · CVE-2021-33193 · published 16 August 2021
CVE-2021-33193: Apache HTTP Server mod_proxy HTTP/2 method validation bypass
Debian · Debian Linux
A crafted method sent over HTTP/2 bypasses validation and is forwarded by mod_proxy, enabling request splitting or cache poisoning. Apache HTTP Server 2.4.17 through 2.4.48 is affected. The flaw matters because it lets an unauthenticated remote client manipulate how requests are parsed downstream, corrupting shared caches or splitting requests.
Description
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityHigh CVSS integrity impact, unauthenticated network reachability, public exploit research, and very high EPSS make this a priority despite no KEV listing.
What it is
A crafted method sent over HTTP/2 bypasses validation and is forwarded by mod_proxy, enabling request splitting or cache poisoning. Apache HTTP Server 2.4.17 through 2.4.48 is affected. The flaw matters because it lets an unauthenticated remote client manipulate how requests are parsed downstream, corrupting shared caches or splitting requests.
Impact
An attacker can poison cached responses or split requests, causing victims to receive attacker-influenced content or have requests routed unexpectedly. The CVSS vector rates integrity impact High with no confidentiality or availability impact.
Attack surface
Reachable over the network via HTTP/2 requests to a server running mod_proxy; the CVSS vector shows no privileges required and no user interaction. Exploitation depends on the deployment using HTTP/2 with mod_proxy in front of backend services.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.46 probability (98.8th percentile), and a PortSwigger research reference is tagged Exploit, indicating public technical detail exists. No ransomware usage is documented.
What to do
- Upgrade Apache HTTP Server to a version after 2.4.48 that contains the mod_proxy HTTP/2 fix.
- Apply the vendor patch commit ecebcc035ccd8d0e2984fe41420d9e944f456b3c or the equivalent distribution update.
- If HTTP/2 is not required, disable it or restrict mod_proxy exposure until patched.
- Review reverse proxy and cache configurations for request smuggling exposure and tighten backend request validation.
Detection
- Inspect HTTP/2 request logs for malformed or unusual method tokens reaching mod_proxy.
- Monitor for duplicate or conflicting request headers and unexpected request splitting patterns in proxy and backend logs.
- Watch cache contents for anomalous or attacker-injected entries and correlate with HTTP/2 client activity.
- Alert on HTTP/2 traffic to unpatched Apache versions 2.4.17 through 2.4.48.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-33193 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33193), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.