Vulnerability record · CVE-2021-44224 · published 20 December 2021
CVE-2021-44224: Apache HTTP Server forward proxy NULL dereference and SSRF
Apache · Http Server
A crafted URI sent to Apache HTTP Server configured as a forward proxy (ProxyRequests on) triggers a NULL pointer dereference crash, and in configurations mixing forward and reverse proxy declarations it can redirect requests to a declared Unix Domain Socket endpoint. The flaw affects versions 2.4.7 through 2.4.51 and matters because it enables both denial of service and server-side request forgery without authentication.
Description
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Automated analysis
high priorityUnauthenticated remote crash and SSRF with a very high EPSS score, though not in KEV and requiring forward proxy configuration.
What it is
A crafted URI sent to Apache HTTP Server configured as a forward proxy (ProxyRequests on) triggers a NULL pointer dereference crash, and in configurations mixing forward and reverse proxy declarations it can redirect requests to a declared Unix Domain Socket endpoint. The flaw affects versions 2.4.7 through 2.4.51 and matters because it enables both denial of service and server-side request forgery without authentication.
Impact
An unauthenticated remote attacker can crash the httpd process, causing denial of service, or in mixed proxy configurations force requests to internal Unix Domain Socket endpoints, enabling SSRF against local services.
Attack surface
Reached over the network by sending a crafted URI to an httpd instance with forward proxy enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.823, 99.6th percentile), indicating elevated likelihood of exploitation activity; references are vendor advisories and third-party advisories, with no public exploit tag.
What to do
- Upgrade Apache HTTP Server to a version after 2.4.51 that contains the fix.
- Disable ProxyRequests unless forward proxying is strictly required.
- Avoid mixing forward and reverse proxy declarations in the same configuration where possible.
- Apply vendor patches for downstream products (Oracle, Debian, Fedora, Apple, Tenable) that bundle affected httpd.
- Restrict network access to proxy-enabled httpd instances to trusted clients.
Detection
- Monitor httpd logs for crashes, segfaults or abnormal process restarts correlated with proxy requests.
- Inspect proxy access logs for malformed or unusual URIs targeting Unix Domain Socket paths.
- Alert on requests to proxy endpoints from unexpected or external source addresses.
- Track httpd version inventory to identify hosts still running 2.4.7 through 2.4.51.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-44224 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44224), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.