CVE-2021-42013 is a critical path traversal vulnerability affecting Apache HTTP Server versions 2.4.49 and 2.4.50, including products from Fedora, NetApp, and Oracle. This flaw allows attackers to access files outside intended directories and, if CGI scripts are enabled, achieve remote code execution. With a CVSS score of 9.8 (Critical) and an EPSS score indicating extremely high exploitability, this vulnerability poses a severe risk. It is actively exploited in the wild, including in ransomware campaigns, with numerous public exploits, Metasploit modules, and significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.49CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.49:*:*:*:*:*:*:* | ||
2.4.50CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.50:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
17.1CPE matchmatch criteria | cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: path traversal and remote code execution (incomplete fix of CVE-2021-41773)
Oct 7, 2021Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project