← back
CVE-2021-36160

mod_proxy_uwsgi out of bound read

EPSS 62.9%CWE-125
In short

A specially crafted web request can cause Apache HTTP Server's mod_proxy_uwsgi module to read beyond its allocated memory, crashing the server and making it unavailable. This affects Apache versions 2.4.30 through 2.4.48.

Technical detail

An out-of-bounds read vulnerability in mod_proxy_uwsgi allows an attacker to craft a malicious URI path that triggers memory access beyond allocated boundaries, resulting in denial of service. The attack requires no authentication and impacts Apache HTTP Server versions 2.4.30 to 2.4.48 when mod_proxy_uwsgi is enabled.

Summary generated and translated by AI from the official description.
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →