CVE-2021-39275 is a critical buffer overflow vulnerability in Apache HTTP Server versions 2.4.48 and earlier, specifically within the ap_escape_quotes() function, which could allow out-of-bounds writes when processing malicious input. While no core modules are affected, third-party modules could expose this flaw. With a CVSS score of 9.8 (CRITICAL), this network-exploitable vulnerability requires no user interaction and can lead to complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no known active exploitation. Community discussion and media coverage are minimal, suggesting low current public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.49CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
Sep 16, 2021ap_escape_quotes buffer overflow
Sep 14, 2021Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project