CVE-2021-33193

Request splitting via HTTP/2 method injection and mod_proxy

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.


We have discovered 612,409 live websites that are affected by CVE-2021-33193.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains612,409 live websites (24% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.17
Vulnerable Versions Count77 versions ( 63% of all versions)



Details

  • Published - Aug 16, 2021
  • Updated - Aug 3, 2024

Credits

  • Reported by James Kettle of PortSwigger

Website Distribution by Country

Number of websites using CVE-2021-33193
United States145,742 websites



Taiwan107,368 websites
Germany49,538 websites
Japan39,813 websites
Netherlands25,101 websites
Russia24,581 websites
France23,728 websites
Czech Republic16,159 websites
Italy15,281 websites
Korea, South14,234 websites

Website Distribution by TLD

Number of websites using CVE-2021-33193
.com282,520 websites
.de35,559 websites
.net24,731 websites
.ru20,978 websites
.org20,526 websites
.nl18,684 websites
.cz13,186 websites
.it12,335 websites
.info11,925 websites
.jp11,393 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-33193

Top websites that are affected by CVE-2021-33193. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
******************.com United States*,***
*******.**.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
See full domain list

FAQ

A total of 612,409 websites have been identified as vulnerable to CVE-2021-33193, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2021-33193 vulnerability.
Apache versions up to and including 2.4.17 are vulnerable to CVE-2021-33193.

References