← back
CVE-2021-33193

Request splitting via HTTP/2 method injection and mod_proxy

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 46%
exploitation probability
46%top 1% of all CVEs
observed exploitation
nono source reports it
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.