CVE-2021-41773 is a critical path traversal vulnerability in Apache HTTP Server 2.4.49, affecting products from vendors like NetApp and Oracle. This flaw allows attackers to access files outside configured directories and, if CGI scripts are enabled, achieve remote code execution. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector and no required user interaction. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.49CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.49:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
17.1CPE matchmatch criteria | cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:* | ||
17.2CPE matchmatch criteria | cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
Oct 12, 2021httpd: path traversal and file disclosure vulnerability
Sep 29, 2021Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project