CVE-2021-41773

critical

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

From the Tenable Blog

CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited
CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited

Published: 2021-10-05

The Apache HTTP Server Project patched a path traversal vulnerability introduced less than a month ago that has been exploited in the wild.Update October 7: The Solution section has been updated to reflect the secondary fix the Apache HTTP Server Project released.

References

https://github.com/Abhishek-Chatterjee-git/cve-workshop

https://github.com/m1-k-k/port-cve-scanner

https://github.com/dhanya-cpu/vulntriage

https://github.com/bonniehkr3/pentest_recon

https://github.com/kalyantiwari2/cve-lookup-tool

https://github.com/Raneem03/cve-analysis-exploitation-mitigation

https://github.com/abdulrafay25-svg/CVE-2021-41773-Exploit

https://github.com/RenatoAntunovic/cve-metasploit-skeniranje

https://github.com/Balckers/mcp-security-server

https://github.com/Payaldinkar/CVE-Scanner

https://github.com/Cyb3rZ3d/aws-purple-team-detection-project

https://github.com/cipher131/cve-exploit-mapper

https://github.com/chengbochuan3/Security-Blog

https://github.com/GlebUsalt/cybersecurity_portfolio

https://github.com/chengbochuan3/CVE-Apache-Ecosystem

https://github.com/chengbochuan3/CVE-Learn

https://github.com/woo4826/security-wave-cve-harness-starter

https://github.com/Emaar1x/CVE-2021-41773

https://github.com/onixor/CVEs

https://github.com/Shams-Ul-Mehmood/CVE-2021-41773-Exploit

https://github.com/joshuaweiiii/CVE_Compass

https://github.com/anubhavroshan1080-hub/argus

https://github.com/KunalKhandelwal-dev/cve-2021-41773-lab

https://github.com/sbimoxa/cve-2021-41773-lab

https://github.com/KunalKhandelwal-dev/cve-2021-41773-source-code-analysis

https://github.com/Nvd1901/CVE-lab-reproduse

https://github.com/abdirahmancadiir7-cmyk/CVE-Vulnerability-Scanner

https://github.com/T-Onix/Snare

https://github.com/GGirishya/CVE_lookup_tools

https://github.com/DappaNISM/mass_cve-2021-41773

https://github.com/RevantVishwakarma/Vulnerability-Lookup-Tool

https://github.com/HaakimSec/zero2shell-50

https://github.com/S8C88/ExploitDB-CLI

https://github.com/1412Kkkkid/cve_2021_41773_reproduction

https://github.com/0xrogg/CVE-2021-41773

https://github.com/ricktor0/CVE-Labs

https://github.com/Abhigiri77/Vulnerability-CVE-Scanner

https://github.com/himanshH710/Syntexchub_Vulnerability--CVE-Scanner

https://github.com/johnwickakash12/CVE-2021-41773

https://github.com/Ninobt/Cybersecurity-Internship-Labs

https://github.com/michaelochoaa/cve-triage-agent

https://github.com/sakethreddy0302/vuln_scanner

https://github.com/eunho87/CVE-2021-42013

https://github.com/Park123r/CVE-2021-41773

https://github.com/korneevscp/osint-target

https://github.com/RootVandal/Netrecon

https://github.com/99-sketch/vuln-research-mcp

https://github.com/Ejikemeilo/CVE-Scanner

https://github.com/sannu1565/Coretern_CVE__Scanner

https://github.com/Martinez17s/FastScan

https://github.com/TechByDami/vulnerability-cve-scanner

https://github.com/raceksd-source/cve-anchor

https://github.com/NovocaineX/pentest-metasploit

https://github.com/trainer80/Common-Vulnerabilities-and-Exposures-CVE-

https://github.com/Joapath/CVE-2021-42013

https://github.com/Joapath/CVE-2021-41773

https://github.com/MohammedAbdulAhadSaud/DotSlash

https://github.com/fDarkShadow/noctis

https://github.com/harshweb-cyber/Netscout

https://github.com/fxdyx-a/CVE-2021-41773-POC

https://github.com/Guppss/VulnScan-Pro

https://github.com/Nixhii/Vulnerability-Scanner

https://github.com/888irdy/cve-research

https://github.com/Kartik0219/vuln-scanner

https://github.com/arsalan-khan-dev/VulnScan-Pro

https://github.com/aimannurzharfan/netguard-sentinel

https://github.com/aimannurzharfan/Netguard-Sentinel

https://github.com/trishab0807-lgtm/home-network-scanner

https://github.com/paulnn12/cve-lab-generator

https://github.com/maxi-schaefer/Aegis

https://github.com/SallyAboud/Vulnerability-Scanner

https://github.com/Silence-Cy/ModuScan

https://github.com/aadov/vuln-management-lab

https://github.com/daecayde/bloodhoundr

https://github.com/Ateebshaikh21/red-team-ai

https://github.com/krish-achanta/vuln-validator

https://github.com/daecayde/nightcrawler

https://github.com/ShacharLF/Network-Scanner

https://github.com/S-Manish-reddy/Vulnerability-Scanner

https://github.com/wvverez/CVE-2021-41773-PoC

https://github.com/youssefelnamer/scanner

https://github.com/4coz/redrecon

https://github.com/zeemanmemon/cve-lookup

https://github.com/saaswat19/Network-Vulnerability-Scanner

https://github.com/preetideepaksoni/Penetration-Testing-Portfolio

https://github.com/akshaykumarsatyala/01-network-vulnerability-scanner

https://github.com/ch0kan/cve-patch-autopsy-path-traversal

https://github.com/akshitrao33/vulnerability-scanner

https://github.com/ODamDam/sec-report-kit

https://github.com/ben-slates/CVE-FINDER

https://github.com/bytezora/recon-x

https://github.com/toppos2/cve-checker

https://github.com/mrjoker-web/ShadowCVE

https://github.com/Sharon-Needles/cve

https://github.com/klmntbelgium/cve-2021-41773-exploration

https://github.com/Omsutaria/NetVulnScanner

https://github.com/Retr0wq/network-scanner

https://github.com/JKIM72403/CS4277-CVE-Path-Traversal-Apache-HTTP-Server

https://github.com/r00tkit77/nessus_mcp_server

https://github.com/elliotisnotavailable/pentest-bench

https://github.com/Sumeru-M/Automated_Vulnerability_scanner

https://github.com/neeljain21/network-security-scanner

https://github.com/Kouf320/docker-lab-cve-2017-5638-cve-2021-41773

https://github.com/Kouf320/attacker-lab-cve-2017-5638-cve-2021-41773-paper

https://github.com/Amine-NAHLI/cve-dataset-generator

https://github.com/Sombra-1/vulnmind

https://github.com/phantom-offensive/AppAssault

https://github.com/Krisparenthetic284/osint-mcp-server

https://github.com/0xBugatti/AwesomeNmap

https://github.com/phantom-offensive/AppAssaultLab

https://github.com/Phantom-C2-77/AppAssaultLab

https://github.com/marez8505/VulnScout

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/maaabtech/vuln-cve-scanner

https://github.com/snapdowgg/CVE-2021-41773

https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner

https://github.com/Chandana375/Syntecxhub_cve-scanner

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/tsiddiquea/cve-reproduction-lab

https://github.com/anwar25kzzz-art/IT-solera---task-3

https://github.com/jamalinux1/syntecxhub-cve-scanner

https://github.com/zubairahm3d/apache-cve-2021-41773-lab

https://github.com/Nanxsec/exploitApache

https://github.com/EngSajjad21/Port-Scanner

https://github.com/IKhaleelS/Syntecxhub_cve_scanner

https://github.com/smailbissis-a11y/net-vuln-scanner

https://github.com/Deloney-code/AI-Powered-Red-Team-Automation

https://github.com/Mujtaba11Riu/Operating-System-Project

https://github.com/Npg-1/CVE_Website

https://github.com/RevShellXD/LFI-Destruction

https://github.com/CVE-ORG/CVE-ORG

https://github.com/sudo-boma/vulnerability-scanner

https://github.com/parvathypjoshy/SENTRIX

https://github.com/ChanaPCN/CVE-2021-41773-Analysis

https://github.com/8BitTacoSupreme/sbom_CVE_dash_demo

https://github.com/rikdek/CVE-2021-41773

https://github.com/alfanowski/X-Scan

https://github.com/alfanoandrea/X-Scan

https://github.com/drackyjr/CVE-2021-42013

https://github.com/FakhriCRD/Apache-CVE-2021-42013-RCE-Exploit

https://github.com/odaysec/PwnTraverse

https://github.com/MuhammadHuzaifaAsif/security-lab

https://github.com/hackedrishi/CTF_WRITEUPS-TryHackMe-CVE-2021-41773-

https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic

https://github.com/charanvoonna/CVE-2021-41773

https://github.com/codewhisperxai/ZeroScanX

https://github.com/cyberleelawat/LeelawatX-CVE-Hunter

https://github.com/r0otk3r/CVE-2021-41773

https://github.com/yigitcantunay35/Reconx

https://github.com/blu3ming/PoC-CVE-2021-41773

https://github.com/freddy913/ctf-challenge

https://github.com/psibot/apache-vulnerable

https://github.com/NZRXHX/NZRXNETSCANNER

https://github.com/b4nxzz/CVEs

https://github.com/CyberQuestor-infosec/CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE

https://github.com/Ask-os/CVE-2021-41773

https://github.com/carvajaldz9/VulnrabilityScanner

https://github.com/sakshiishukla/Python-Vulnerability-Scanner

https://github.com/khaidtraivch/CVE-2021-41773-Apache-2.4.49-

https://github.com/MagicGautam/CVEs-Proof-Of-Concept

https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks

https://github.com/javaamo/CVE-2021-41773

https://github.com/Vanshuk-Bhagat/Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-42013

https://github.com/XDUgaile/CVE-Scanner-Tool

https://github.com/qhoko/CVE

https://github.com/FakesiteSecurity/CVE-2021-41773

https://github.com/redspy-sec/CVE-2021-41773

https://github.com/ucsb-seclab/CVEX-records

Details

Source: Mitre, NVD

Published: 2021-10-05

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99992