Apache 2.4.48 and below contain an issue where uri-path can cause mod_proxy to forward the request to an origin server chosen by the remote user.
id: CVE-2021-40438
info:
name: Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
author:
...