In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.debian.org/security/2021/dsa-4937
https://security.netapp.com/advisory/ntap-20210702-0001/
https://security.gentoo.org/glsa/202107-38
https://lists.debian.org/debian-lts-announce/2021/07/msg00006.html