A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
Published: 2021-10-05
The Apache HTTP Server Project patched a path traversal vulnerability introduced less than a month ago that has been exploited in the wild.Update October 7: The Solution section has been updated to reflect the secondary fix the Apache HTTP Server Project released.
https://hackread.com/linux-cryptominer-using-legit-sites-to-spread-malware/
https://thehackernews.com/2025/07/hackers-exploit-apache-http-server-flaw.html
https://www.edgescan.com/wp-content/uploads/2024/03/2023-Vulnerability-Statistics-Report.pdf
https://isc.sans.edu/diary/rss/31528
https://www.infosecurity-magazine.com/news/androxgh0st-botnet-adopts-mozi/
https://hackread.com/androxgh0st-botnet-integrate-mozi-iot-vulnerabilities/
https://github.com/Abhishek-Chatterjee-git/cve-workshop
https://github.com/m1-k-k/port-cve-scanner
https://github.com/dhanya-cpu/vulntriage
https://github.com/bonniehkr3/pentest_recon
https://github.com/kalyantiwari2/cve-lookup-tool
https://github.com/Raneem03/cve-analysis-exploitation-mitigation
https://github.com/abdulrafay25-svg/CVE-2021-41773-Exploit
https://github.com/RenatoAntunovic/cve-metasploit-skeniranje
https://github.com/Balckers/mcp-security-server
https://github.com/Payaldinkar/CVE-Scanner
https://github.com/Cyb3rZ3d/aws-purple-team-detection-project
https://github.com/cipher131/cve-exploit-mapper
https://github.com/chengbochuan3/Security-Blog
https://github.com/GlebUsalt/cybersecurity_portfolio
https://github.com/chengbochuan3/CVE-Apache-Ecosystem
https://github.com/chengbochuan3/CVE-Learn
https://github.com/woo4826/security-wave-cve-harness-starter
https://github.com/Emaar1x/CVE-2021-41773
https://github.com/onixor/CVEs
https://github.com/Shams-Ul-Mehmood/CVE-2021-41773-Exploit
https://github.com/joshuaweiiii/CVE_Compass
https://github.com/anubhavroshan1080-hub/argus
https://github.com/KunalKhandelwal-dev/cve-2021-41773-lab
https://github.com/sbimoxa/cve-2021-41773-lab
https://github.com/KunalKhandelwal-dev/cve-2021-41773-source-code-analysis
https://github.com/Nvd1901/CVE-lab-reproduse
https://github.com/abdirahmancadiir7-cmyk/CVE-Vulnerability-Scanner
https://github.com/T-Onix/Snare
https://github.com/GGirishya/CVE_lookup_tools
https://github.com/DappaNISM/mass_cve-2021-41773
https://github.com/RevantVishwakarma/Vulnerability-Lookup-Tool
https://github.com/HaakimSec/zero2shell-50
https://github.com/S8C88/ExploitDB-CLI
https://github.com/1412Kkkkid/cve_2021_41773_reproduction
https://github.com/0xrogg/CVE-2021-41773
https://github.com/ricktor0/CVE-Labs
https://github.com/Abhigiri77/Vulnerability-CVE-Scanner
https://github.com/himanshH710/Syntexchub_Vulnerability--CVE-Scanner
https://github.com/johnwickakash12/CVE-2021-41773
https://github.com/Ninobt/Cybersecurity-Internship-Labs
https://github.com/michaelochoaa/cve-triage-agent
https://github.com/sakethreddy0302/vuln_scanner
https://github.com/eunho87/CVE-2021-42013
https://github.com/Park123r/CVE-2021-41773
https://github.com/korneevscp/osint-target
https://github.com/RootVandal/Netrecon
https://github.com/99-sketch/vuln-research-mcp
https://github.com/Ejikemeilo/CVE-Scanner
https://github.com/sannu1565/Coretern_CVE__Scanner
https://github.com/Martinez17s/FastScan
https://github.com/TechByDami/vulnerability-cve-scanner
https://github.com/raceksd-source/cve-anchor
https://github.com/NovocaineX/pentest-metasploit
https://github.com/trainer80/Common-Vulnerabilities-and-Exposures-CVE-
https://github.com/Joapath/CVE-2021-42013
https://github.com/Joapath/CVE-2021-41773
https://github.com/MohammedAbdulAhadSaud/DotSlash
https://github.com/fDarkShadow/noctis
https://github.com/harshweb-cyber/Netscout
https://github.com/fxdyx-a/CVE-2021-41773-POC
https://github.com/Guppss/VulnScan-Pro
https://github.com/Nixhii/Vulnerability-Scanner
https://github.com/888irdy/cve-research
https://github.com/Kartik0219/vuln-scanner
https://github.com/arsalan-khan-dev/VulnScan-Pro
https://github.com/aimannurzharfan/netguard-sentinel
https://github.com/aimannurzharfan/Netguard-Sentinel
https://github.com/trishab0807-lgtm/home-network-scanner
https://github.com/paulnn12/cve-lab-generator
https://github.com/maxi-schaefer/Aegis
https://github.com/SallyAboud/Vulnerability-Scanner
https://github.com/Silence-Cy/ModuScan
https://github.com/aadov/vuln-management-lab
https://github.com/daecayde/bloodhoundr
https://github.com/Ateebshaikh21/red-team-ai
https://github.com/krish-achanta/vuln-validator
https://github.com/daecayde/nightcrawler
https://github.com/ShacharLF/Network-Scanner
https://github.com/S-Manish-reddy/Vulnerability-Scanner
https://github.com/wvverez/CVE-2021-41773-PoC
https://github.com/youssefelnamer/scanner
https://github.com/4coz/redrecon
https://github.com/zeemanmemon/cve-lookup
https://github.com/saaswat19/Network-Vulnerability-Scanner
https://github.com/preetideepaksoni/Penetration-Testing-Portfolio
https://github.com/akshaykumarsatyala/01-network-vulnerability-scanner
https://github.com/ch0kan/cve-patch-autopsy-path-traversal
https://github.com/akshitrao33/vulnerability-scanner
https://github.com/ODamDam/sec-report-kit
https://github.com/ben-slates/CVE-FINDER
https://github.com/bytezora/recon-x
https://github.com/toppos2/cve-checker
https://github.com/mrjoker-web/ShadowCVE
https://github.com/Sharon-Needles/cve
https://github.com/klmntbelgium/cve-2021-41773-exploration
https://github.com/Omsutaria/NetVulnScanner
https://github.com/Retr0wq/network-scanner
https://github.com/JKIM72403/CS4277-CVE-Path-Traversal-Apache-HTTP-Server
https://github.com/r00tkit77/nessus_mcp_server
https://github.com/elliotisnotavailable/pentest-bench
https://github.com/Sumeru-M/Automated_Vulnerability_scanner
https://github.com/neeljain21/network-security-scanner
https://github.com/Kouf320/docker-lab-cve-2017-5638-cve-2021-41773
https://github.com/Kouf320/attacker-lab-cve-2017-5638-cve-2021-41773-paper
https://github.com/Amine-NAHLI/cve-dataset-generator
https://github.com/Sombra-1/vulnmind
https://github.com/phantom-offensive/AppAssault
https://github.com/Krisparenthetic284/osint-mcp-server
https://github.com/0xBugatti/AwesomeNmap
https://github.com/phantom-offensive/AppAssaultLab
https://github.com/Phantom-C2-77/AppAssaultLab
https://github.com/marez8505/VulnScout
https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro
https://github.com/maaabtech/vuln-cve-scanner
https://github.com/snapdowgg/CVE-2021-41773
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/Chandana375/Syntecxhub_cve-scanner
https://github.com/RehmanAjaz/CVE-Scanner
https://github.com/tsiddiquea/cve-reproduction-lab
https://github.com/anwar25kzzz-art/IT-solera---task-3
https://github.com/jamalinux1/syntecxhub-cve-scanner
https://github.com/zubairahm3d/apache-cve-2021-41773-lab
https://github.com/Nanxsec/exploitApache
https://github.com/EngSajjad21/Port-Scanner
https://github.com/IKhaleelS/Syntecxhub_cve_scanner
https://github.com/smailbissis-a11y/net-vuln-scanner
https://github.com/Deloney-code/AI-Powered-Red-Team-Automation
https://github.com/Mujtaba11Riu/Operating-System-Project
https://github.com/Npg-1/CVE_Website
https://github.com/RevShellXD/LFI-Destruction
https://github.com/CVE-ORG/CVE-ORG
https://github.com/sudo-boma/vulnerability-scanner
https://github.com/parvathypjoshy/SENTRIX
https://github.com/ChanaPCN/CVE-2021-41773-Analysis
https://github.com/8BitTacoSupreme/sbom_CVE_dash_demo
https://github.com/rikdek/CVE-2021-41773
https://github.com/alfanowski/X-Scan
https://github.com/alfanoandrea/X-Scan
https://github.com/drackyjr/CVE-2021-42013
https://github.com/FakhriCRD/Apache-CVE-2021-42013-RCE-Exploit
https://github.com/odaysec/PwnTraverse
https://github.com/MuhammadHuzaifaAsif/security-lab
https://github.com/hackedrishi/CTF_WRITEUPS-TryHackMe-CVE-2021-41773-
https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic
https://github.com/charanvoonna/CVE-2021-41773
https://github.com/codewhisperxai/ZeroScanX
https://github.com/cyberleelawat/LeelawatX-CVE-Hunter
https://github.com/r0otk3r/CVE-2021-41773
https://github.com/yigitcantunay35/Reconx
https://github.com/blu3ming/PoC-CVE-2021-41773
https://github.com/freddy913/ctf-challenge
https://github.com/psibot/apache-vulnerable
https://github.com/NZRXHX/NZRXNETSCANNER
https://github.com/b4nxzz/CVEs
https://github.com/CyberQuestor-infosec/CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE
https://github.com/Ask-os/CVE-2021-41773
https://github.com/carvajaldz9/VulnrabilityScanner
https://github.com/sakshiishukla/Python-Vulnerability-Scanner
https://github.com/khaidtraivch/CVE-2021-41773-Apache-2.4.49-
https://github.com/MagicGautam/CVEs-Proof-Of-Concept
https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
https://github.com/javaamo/CVE-2021-41773
https://github.com/XDUgaile/CVE-Scanner-Tool
https://github.com/FakesiteSecurity/CVE-2021-41773