← back
CVE-2021-33193

Request splitting via HTTP/2 method injection and mod_proxy

EPSS 46.2%
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →