Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-44521

71
FAUCET Score

CVE-2021-44521 describes a critical remote code execution (RCE) vulnerability in Apache Cassandra when specific, documented-as-unsafe user-defined function (UDF) configurations are enabled. An attacker with sufficient permissions to create UDFs can leverage this to execute arbitrary code on the host. This vulnerability carries a CVSS score of 9.1 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed in the KEV catalog, exploit intelligence indicates the availability of Nuclei templates for exploitation, and it has garnered significant community discussion and media coverage, suggesting active interest in its exploitation potential.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.0.26CPE matchmatch criteria
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.12CPE matchmatch criteria
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.0.2CPE matchmatch criteria
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
54.73%
Probability of exploitation in next 30 days
EPSS Percentile
98.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2021-44521 · Mar 2, 2022
This CVE's current EPSS score of 0.5473 is in the 99th percentile among its peer group of 462 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

mavenpatch availablevia ghsa
Product: org.apache.cassandra:cassandra-allFixed in: 3.0.26
mavenpatch availablevia ghsa
Product: org.apache.cassandra:cassandra-allFixed in: 3.11.12
mavenpatch availablevia ghsa
Product: org.apache.cassandra:cassandra-allFixed in: 4.0.2
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: cassandra
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/ocs-must-gather-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/ocs-rhel9-operator
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-multicluster-rhel9-operator
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/rook-ceph-rhel9-operator

Vendor Advisories (2)

mavenGHSA-8ffc-79xg-29w8critical

Apache Cassandra vulnerable to Code Injection due to unsafe configuration

Feb 12, 2022
redhatCVE-2021-44521Moderate

cassandra: RCE for scripted UDFs

Feb 11, 2022

References

jfrog.com / blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution
ExploitMitigationThird Party Advisory
lists.apache.org / thread/y4nb9s4co34j8hdfmrshyl09lokm7356
Issue TrackingMailing ListVendor Advisory
security.netapp.com / advisory/ntap-20220225-0001
Third Party Advisory
openwall.com / lists/oss-security/2022/02/11/4
Mailing ListThird Party Advisory