Furthermore, that particular CVE only creates a vulnerable configuration if they're running Apache httpd with mod_rewrite or mod_proxy. Which means if you aren't running those modules, that vuln isn't a vuln. LOTS of vulns with big scary CVSS numbers aren't actually a vulnerability unless you're using the software with specific configurations enabled.
For fucks sake, at least read the goddamn CVE links.
https://nvd.nist.gov/vuln/detail/CVE-2024-38476
https://httpd.apache.org/security/vulnerabilities_24.html
I'd block you too if you showed up smearing my app with no more evidence than a low effort nmap.