CVE-2021-44790 is a critical buffer overflow vulnerability affecting Apache HTTP Server versions 2.4.51 and earlier, specifically within the mod_lua multipart parser when processing crafted request bodies. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While the Apache team is not aware of active exploits, an ExploitDB entry exists, and the vulnerability has garnered significant community discussion and media coverage, indicating high interest and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.52CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_lua: Possible buffer overflow when parsing multipart content
Dec 20, 2021Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
Dec 14, 2021Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project