CVE-2021-33193 describes a vulnerability in Apache HTTP Server versions 2.4.17 to 2.4.48 where a specially crafted HTTP/2 method can bypass validation in mod_proxy, leading to request splitting or cache poisoning. This vulnerability has a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity and has a high impact on integrity. While the vulnerability is significant, there is no evidence of active exploitation, readily available exploit code (Metasploit, Nuclei, ExploitDB), or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 2.4.17, < 2.4.49CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
<= 5.19.1CPE matchmatch criteria | cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025Request splitting via HTTP/2 method injection and mod_proxy
Aug 10, 2021httpd: Request splitting via HTTP/2 method injection and mod_proxy
Aug 5, 2021Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project