CVE detail
CVE-2021-41773
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 14.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
22 source links · newest first
RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, CCTV systems, and servers, active globally since June. Trend Micro researchers reported that the RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, NVRs, CCTV systems, and web servers, active globally since June. Experts noted that the latest […]
newssecurityaffairs.comOct 10, 2025, 7:33 AMA joint advisory from CISA and the FBI warns about Androxgh0st malware attacks ensnaring devices in a botnet.
newswww.securityweek.comJan 17, 2024, 3:48 PMU.S. CISA and the FBI warned of AndroxGh0st malware used to create a botnet for victim identification and exploitation in target networks. US CISA and the Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA) to warn of AndroxGh0st malware. The malware is spreading to create a botnet for victim identification and exploitation in target networks. […]
newssecurityaffairs.comJan 17, 2024, 12:10 PMThe number of fileless or memory-based attacks that exploit existing software, applications, and protocols have surged 1,400% in the last year. That’s according to Aqua Security’s 2023 Cloud Native Threat Report, which summarizes research and observations of threat actors’ changing tactics, techniques, and procedures (TTPs), along with outlining strategies for protecting cloud environments. Based on […]
newswww.csoonline.comJun 27, 2023, 8:00 AMRezilion uncovered the presence of hundreds of Docker container images containing vulnerabilities that are not detected by most standard vulnerability scanners and SCA tools. The research revealed numerous high-severity/critical vulnerabilities hidden in hundreds of popular container images, downloaded billions of times collectively. This includes high-profile vulnerabilities with publicly known exploits. Some of the hidden vulnerabilities are known to be actively exploited in the wild and are part of the CISA known exploited vulnerabilities catalog, including … More →
newswww.helpnetsecurity.comFeb 23, 2023, 11:00 AMThe Unit 42 Incident Response Report includes insights on which software vulnerabilities are commonly exploited for initial access and a description of how attacker behavior around zero-day vulnerabilities is shifting.
vendorunit42.paloaltonetworks.comJul 26, 2022, 10:00 AMThe 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.
vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PMThe operators of the EnemyBot botnet added exploits for recently disclosed flaws in VMware, F5 BIG-IP, and Android systems. Operators behind the EnemyBot botnet are expanding the list of potential targets adding exploits for recently disclosed critical vulnerabilities in from VMware, F5 BIG-IP, and Android. The botnet was first discovered by Fortinet in March, the […]
newssecurityaffairs.comMay 30, 2022, 7:09 AM- Enemybot, a new DDoS botnet appears in the threat landscapeSecurity Affairs
Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities. Researchers from Fortinet discovered a new DDoS botnet, tracked as Enemybot, that has targeted several routers and web servers by exploiting known vulnerabilities. The botnet targets multiple architectures, including arm, bsd, x64, and x86. The researchers attribute the botnet […]
newssecurityaffairs.comApr 17, 2022, 5:53 PM A recently identified DDoS botnet has targeted several router models and various types of web servers by exploiting known vulnerabilities, Fortinet warns.
newswww.securityweek.comApr 15, 2022, 10:41 AMNetwork attacks observed August-October 2021 included high levels of cross-site scripting, code execution and directory traversal.
vendorunit42.paloaltonetworks.comDec 21, 2021, 8:00 PM- Fuzzing sockets: Apache HTTP, Part 3: ResultsGitHub Security Lab
In this third and last part, I’ll share the results of my research on Apache HTTP server, and I’ll show some of the vulnerabilities that I’ve found.
vendorgithub.blogDec 21, 2021, 6:36 PM German Cybersecurity Agency and Cisco Warn of Attacks Targeting Apache HTTP Server Flaw Organizations are being advised to ensure that their Apache HTTP servers are up to date, after it came to light that a recently patched vulnerability has been exploited in attacks.
newswww.securityweek.comNov 29, 2021, 12:10 PM- Apache CVE-2021-41773, CVE-2021-42013Horizon3.ai
We wanted to do something a little bit different with this post. Our vulnerability disclosures, exploit proof-of-concepts, and attack analysis blog posts have been awesome, but they have been catering to an offensive security audience.
exploithorizon3.aiOct 18, 2021, 8:17 PM - 11th October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches UK newspaper & Media outlet The Telegraph has accidently leaked 10 TB of subscribers’ data after leaving an Elasticsearch cluster unsecured. Leakage includes internal logs, names, emails, device type, URL requests, IP […]
vendorresearch.checkpoint.comOct 11, 2021, 2:26 PM - Security Affairs newsletter Round 335Security Affairs
A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the international press subscribe here. Previously undetected FontOnLake Linux malware used in targeted attacks Google addresses four high-severity flaws in Chrome Security […]
newssecurityaffairs.comOct 10, 2021, 1:07 PM Security expert Dhiraj Mishra published an NMAP script for the CVE-2021-41773 Path Traversal vulnerability affecting Apache Web Server version 2.4.49. Security researcher Dhiraj Mishra released an NMAP script for the CVE-2021-41773 path traversal vulnerability affecting Apache Web Server version 2.4.49. This week Apache Software Foundation has released HTTP Web Server 2.4.51 to address an actively exploited path […]
newssecurityaffairs.comOct 9, 2021, 12:03 PMThe Apache HTTP Server Project on Thursday announced the release of another update in response to a recently discovered zero-day vulnerability after determining that the initial fix was incomplete.
newswww.securityweek.comOct 8, 2021, 11:03 AM- Apache rolled out a new update in a few days to fix incomplete patch for an actively exploited flawSecurity Affairs
Apache Software Foundation has released HTTP Web Server 2.4.51 to completely address a vulnerability that has been actively exploited in the wild. Apache Software Foundation has released HTTP Web Server 2.4.51 to address an actively exploited path traversal vulnerability (CVE-2021-41773) that was only partially addressed with a previous release. An attacker can trigger the flaw […]
newssecurityaffairs.comOct 8, 2021, 7:38 AM Users are urged to immediately patch an Apache HTTP Server zero-day vulnerability that has been exploited in the wild. More than 100,000 servers appear to be exposed to attacks.
newswww.securityweek.comOct 6, 2021, 11:06 AM- Apache patch a zero-day flaw exploited in the wildSecurity Affairs
Apache has addressed two vulnerabilities, one of which is a path traversal and file disclosure flaw in its HTTP server actively exploited in the wild. Apache has rolled out security patches to address two flaws, including a path traversal and file disclosure issue in its HTTP server that is actively exploited in the wild. The […]
newssecurityaffairs.comOct 5, 2021, 5:15 PM - [Updated, again] Apache fixes zero-day vulnerability in HTTP ServerMalwarebytes Labs
The Apache HTTP Server 2.4.49 is vulnerable to a flaw that allows attackers to use a path traversal attack to map…
newswww.malwarebytes.comOct 5, 2021, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
3 repository references · best confidence 0.99 · max 1 stars
- im2sinister/CVE-2021-41773High confidencegithubRepository topic discovery1 starsDiscovered Jul 15, 2026, 4:51 AM
- vulnerability-writeup/cve-2021-41773Medium confidencegitlabDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 6:51 PM
- gagaltotal/CVE-2021-41773-apacheHigh confidencegithubRepository topic discovery0 starsDiscovered Jul 23, 2026, 10:51 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-42013CVSS 9.8 · Critical
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the director…
- CVE-2021-44790CVSS 9.8 · Critical
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an expl…
- CVE-2021-41524CVSS 7.5 · High
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specia…
- CVE-2021-39275CVSS 9.8 · Critical
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules…
- CVE-2021-36160CVSS 7.5 · High
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48…
- CVE-2021-34798CVSS 7.5 · High
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.