← Vulnerability feed

Vulnerability record · CVE-2021-44224 · published 20 December 2021

CVE-2021-44224: Apache HTTP Server forward proxy NULL dereference and SSRF

Apache · Http Server

A crafted URI sent to Apache HTTP Server configured as a forward proxy (ProxyRequests on) triggers a NULL pointer dereference crash, and in configurations mixing forward and reverse proxy declarations it can redirect requests to a declared Unix Domain Socket endpoint. The flaw affects versions 2.4.7 through 2.4.51 and matters because it enables both denial of service and server-side request forgery without authentication.

8.2 CVSS 3.1 High EPSS 82% · top 0.3% CWE-476 · NULL pointer dereference
8.2CVSS 3.1 base score, v2 6.4
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
38References
17 Jun 2026Last modified by NVD

Description

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote crash and SSRF with a very high EPSS score, though not in KEV and requiring forward proxy configuration.

What it is

A crafted URI sent to Apache HTTP Server configured as a forward proxy (ProxyRequests on) triggers a NULL pointer dereference crash, and in configurations mixing forward and reverse proxy declarations it can redirect requests to a declared Unix Domain Socket endpoint. The flaw affects versions 2.4.7 through 2.4.51 and matters because it enables both denial of service and server-side request forgery without authentication.

Impact

An unauthenticated remote attacker can crash the httpd process, causing denial of service, or in mixed proxy configurations force requests to internal Unix Domain Socket endpoints, enabling SSRF against local services.

Attack surface

Reached over the network by sending a crafted URI to an httpd instance with forward proxy enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.823, 99.6th percentile), indicating elevated likelihood of exploitation activity; references are vendor advisories and third-party advisories, with no public exploit tag.

What to do

  • Upgrade Apache HTTP Server to a version after 2.4.51 that contains the fix.
  • Disable ProxyRequests unless forward proxying is strictly required.
  • Avoid mixing forward and reverse proxy declarations in the same configuration where possible.
  • Apply vendor patches for downstream products (Oracle, Debian, Fedora, Apple, Tenable) that bundle affected httpd.
  • Restrict network access to proxy-enabled httpd instances to trusted clients.

Detection

  • Monitor httpd logs for crashes, segfaults or abnormal process restarts correlated with proxy requests.
  • Inspect proxy access logs for malformed or unusual URIs targeting Unix Domain Socket paths.
  • Alert on requests to proxy endpoints from unexpected or external source addresses.
  • Track httpd version inventory to identify hosts still running 2.4.7 through 2.4.51.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
http://seclists.org/fulldisclosure/2022/May/33 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2022/May/35 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2022/May/38 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/20/3 Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUB
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2N
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZU
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKU
https://security.gentoo.org/glsa/202208-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20211224-0001/ Third Party Advisory
https://support.apple.com/kb/HT213255 Third Party Advisory
https://support.apple.com/kb/HT213256 Third Party Advisory
https://support.apple.com/kb/HT213257 Third Party Advisory
https://www.debian.org/security/2022/dsa-5035 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.tenable.com/security/tns-2022-01 Third Party Advisory
https://www.tenable.com/security/tns-2022-03 Third Party Advisory
http://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
http://seclists.org/fulldisclosure/2022/May/33 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2022/May/35 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2022/May/38 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/20/3 Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUB
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2N
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZU
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKU
https://security.gentoo.org/glsa/202208-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20211224-0001/ Third Party Advisory
https://support.apple.com/kb/HT213255 Third Party Advisory
https://support.apple.com/kb/HT213256 Third Party Advisory
https://support.apple.com/kb/HT213257 Third Party Advisory
https://www.debian.org/security/2022/dsa-5035 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.tenable.com/security/tns-2022-01 Third Party Advisory
https://www.tenable.com/security/tns-2022-03 Third Party Advisory

Track CVE-2021-44224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-43300Apple iOS, iPadOS and macOS out-of-bounds write via malicious imageAn out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states th…KEVEPSS 22%analysed10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed

Source: NIST National Vulnerability Database (record CVE-2021-44224), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.