In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.871
EPSS Ranking 99.4%