CVE-2021-33193
published 2021-08-16CVE-2021-33193: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue…
PriorityP358high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
46.18%
98.7th percentile
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.17 < 2.4.49 | 2.4.49 |
| apache_software_foundation | apache_http_server | — | — |
| debian | apache2 | < apache2 2.4.48-4 (bookworm) | apache2 2.4.48-4 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_httpd_2.4.52-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_httpd_2.4.46-6_on_cbl_mariner_1.0 | — | — |
| oracle | secure_backup | < 18.1.0.1.0 | 18.1.0.1.0 |
| oracle | zfs_storage_appliance_kit | — | — |
| tenable | tenable.sc | <= 5.19.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_cisco9.0CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
vendor_cisco·2021-11-24·CVSS 9.0
CVE-2021-33193 [CRITICAL] CWE-120 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
On September 16, 2021, the Apache Software Foundation disclosed five vulnerabilities affecting the Apache HTTP Server (httpd) 2.4.48 and earlier releases.
For a description of these vulnerabilities, see the Apache HTTP Server 2.4.49 section of the Apache HTTP Server 2.4 vulnerabilities webpage.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2021-09-28·CVSS 7.5
[HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-5090-1 introduced a regression in Apache HTTP Server.
USN-5090-1 fixed vulnerabilities in Apache HTTP Server. One of the upstream
fixes introduced a regression in UDS URIs. This update fixes the problem.
Original advisory details:
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi mod
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-09-27·CVSS 7.5
CVE-2021-34798 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly
handled certain request uri-paths. A remote attacker could possibly use
this issue to cause the server to crash, resulting in a denial of service.
This issue
Microsoft
Request splitting via HTTP/2 method injection and mod_proxy
vendor_msrc·2021-08-10·CVSS 7.5
CVE-2021-33193 [HIGH] Request splitting via HTTP/2 method injection and mod_proxy
Request splitting via HTTP/2 method injection and mod_proxy
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:/
Red Hat
httpd: Request splitting via HTTP/2 method injection and mod_proxy
vendor_redhat·2021-08-05·CVSS 7.5
CVE-2021-33193 [HIGH] CWE-476 httpd: Request splitting via HTTP/2 method injection and mod_proxy
httpd: Request splitting via HTTP/2 method injection and mod_proxy
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
A NULL pointer dereference was found in Apache httpd mod_h2. The highest threat from this flaw is to system integrity.
Mitigation: This flaw can be mitigated by disabling HTTP/2. More information available at: https://httpd.apache.org/docs/2.4/mod/mod_http2.html
Package: httpd (Red Hat Enterprise Linux 6) - Out of support scope
Package: httpd (Red Hat Enterprise Linux 7) - Out of support scope
Package: httpd (Red Hat Enterprise Linux 9) - Not affected
Package: httpd22 (Red Hat JBoss Enterprise Application Platform 6)
Debian
CVE-2021-33193: apache2 - A crafted method sent through HTTP/2 will bypass validation and be forwarded by ...
vendor_debian·2021·CVSS 7.5
CVE-2021-33193 [HIGH] CVE-2021-33193: apache2 - A crafted method sent through HTTP/2 will bypass validation and be forwarded by ...
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
Scope: local
bookworm: resolved (fixed in 2.4.48-4)
bullseye: resolved (fixed in 2.4.48-3.1+deb11u1)
forky: resolved (fixed in 2.4.48-4)
sid: resolved (fixed in 2.4.48-4)
trixie: resolved (fixed in 2.4.48-4)
Cisco
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
vendor_cisco·CVSS 3.1
CVE-2021-33193 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
CVE-2021-33193: Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
On September 16, 2021, the Apache Software Foundation disclosed five vulnerabilities affecting the Apache HTTP Server (httpd) 2.4.48 and earlier releases. For a description of these vulnerabilities, see the Apache HTTP Server 2.4.49 section of the Apache HTTP Server 2.4 vulnerabilities webpage. This advisory will be updated as additional information becomes available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
CVSS: 3.1
CWE: CWE-120, CWE-125, CWE-476, CWE-120, CWE-125, CWE-476, CWE-918, CWE-120, CWE-125, CWE-476, CWE-120, CWE-125, CWE-476, CWE-918
Bug IDs: CSCwa33065,
GHSA
GHSA-p9fg-6rr5-38xc: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning
ghsa_unreviewed·2022-05-24
CVE-2021-33193 [HIGH] GHSA-p9fg-6rr5-38xc: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
OSV
apache2 regression
osv·2021-09-28·CVSS 7.5
CVE-2021-33193 [HIGH] apache2 regression
apache2 regression
USN-5090-1 fixed vulnerabilities in Apache HTTP Server. One of the upstream
fixes introduced a regression in UDS URIs. This update fixes the problem.
Original advisory details:
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly
handled certain request uri-paths. A remote attacker could possibly us
OSV
apache2 vulnerabilities
osv·2021-09-27·CVSS 7.5
CVE-2021-33193 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly
handled certain request uri-paths. A remote attacker could possibly use
this issue to cause the server to crash, resulting in a denial of service.
This issue only affected Ubuntu 20.04 LTS and Ubuntu 21.04.
(CVE-2021-36160)
It was discovered t
OSV
CVE-2021-33193: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning
osv·2021-08-16·CVSS 7.5
CVE-2021-33193 [HIGH] CVE-2021-33193: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
No detection rules found.
No public exploits indexed.
https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patchhttps://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2023/03/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/https://portswigger.net/research/http2https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20210917-0004/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.tenable.com/security/tns-2021-17https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patchhttps://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2023/03/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/https://portswigger.net/research/http2https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20210917-0004/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.tenable.com/security/tns-2021-17
2021-08-16
Published