CVE-2021-36160 is a denial-of-service vulnerability affecting Apache HTTP Server versions 2.4.30 to 2.4.48, specifically within the mod_proxy_uwsgi module. A specially crafted request URI-path can lead to an out-of-bounds read, causing the server to crash. Rated with a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity and no user interaction required, resulting in a complete loss of availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.30, < 2.4.49CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path
Sep 16, 2021mod_proxy_uwsgi out of bound read
Sep 14, 2021Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project