CVE-2012-4001: Google Mod Pagespeed

Medium severity, CVSS 5.0. EPSS: 0.7% chance of exploitation in the next 30 days.

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.

Affected products

  • Google Mod Pagespeed: up to and including 0.10.22.4; version 0.10.19.1 only

Published 2012-09-15. Last modified 2026-06-16.