CVE-2021-41773
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 99.99% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- high · CWE-22
- Published
- 2021-10-05
- Updated
- 2025-10-21
Proof-of-concept exploits (176)
- http://packetstormsecurity.com/files/164418/Apache-HTTP-Server-2.4.49-Path-Traversal-Remo…
- http://packetstormsecurity.com/files/164418/Apache-HTTP-Server-2.4.49-Path-Traversal.html
- http://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Ex…
- http://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Executi…
- 0xGabe/Apache-CVEs0★ · 2023-06-03
- 0xRar/CVE-2021-417737★ · 2021-10-08
- 0xc4t/CVE-2021-417730★ · 2024-08-27
- 12345qwert123456/CVE-2021-417730★ · 2022-11-21
- 1nhann/CVE-2021-417739★ · 2021-10-08
- 5gstudent/cve-2021-41773-and-cve-2021-420132★ · 2021-10-09
- Aezlan/ProjectMagenta-Site-Building0★ · 2023-03-10
- Amit29533/Global-Attack-Map0★ · 2025-08-11
- AnonymouID/POC2★ · 2022-04-25
- AssassinUKG/CVE-2021-417731★ · 2021-10-20
- AzK-os-dev/CVE-2021-417730★ · 2025-05-28
- BabyTeam1024/CVE-2021-417730★ · 2021-10-22
- BlueTeamSteve/CVE-2021-4177323★ · 2021-10-06
- CalfCrusher/Path-traversal-RCE-Apache-2.4.49-2.4.50-Exploit10★ · 2022-04-08
- Chocapikk/CVE-2021-417732★ · 2022-04-12
- ComdeyOverflow/CVE-2021-417736★ · 2022-11-15
- CyberQuestor-infosec/CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE2★ · 2025-06-12
- DoTuan1/Reserch-CVE-2021-417730★ · 2022-03-31
- EagleTube/CVE-2021-417731★ · 2021-10-09
- Fa1c0n35/CVE-2021-417730★ · 2022-03-14
- FakesiteSecurity/CVE-2021-417730★ · 2025-01-03
- HITOUBEN/MSPR30★ · 2025-09-27
- Habib0x0/CVE-2021-417732★ · 2022-12-11
- Hattan-515/POC-CVE-2021-417730★ · 2021-10-07
- Hattan515/POC-CVE-2021-417730★ · 2021-10-07
- HernanRodriguez1/Dorks-Shodan-2023247★ · 2025-01-13
- Hydragyrum/CVE-2021-41773-Playground6★ · 2021-11-04
- IcmpOff/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit1★ · 2021-11-09
- Iris288/CVE-2021-417731★ · 2023-11-20
- JIYUN02/cve-2021-417730★ · 2025-04-25
- K3ysTr0K3R/CVE-2021-42013-EXPLOIT7★ · 2024-01-15
- LayarKacaSiber/CVE-2021-417730★ · 2021-10-23
- Ls4ss/CVE-2021-41773_CVE-2021-4201320★ · 2026-03-23
- LudovicPatho/CVE-2021-417735★ · 2022-10-26
- MagicGautam/CVEs-Proof-Of-Concept0★ · 2025-04-19
- MatanelGordon/docker-cve-2021-417730★ · 2023-04-21
- Maybe4a6f7365/CVE-2021-417730★ · 2024-06-03
- MazX0p/CVE-2021-417731★ · 2021-10-25
- NoTsPepino/Shodan-Dorking3★ · 2024-06-27
- OfriOuzan/CVE-2021-41773_CVE-2021-42013_Exploits4★ · 2023-08-02
- PentesterGuruji/CVE-2021-417731★ · 2021-10-07
- Ramiyuu/redteamtools0★ · 2025-09-22
- RyouYoo/CVE-2021-4177313★ · 2021-10-05
- Soliux/CVE-2021-417732★ · 2021-11-11
- TAI-REx/cve-2021-41773-nse0★ · 2021-10-06
- Taldrid1/cve-2021-417730★ · 2025-01-07
- ThatNotEasy/Apache-PathTraversal0★ · 2024-10-25
- TheKernelPanic/exploit-apache2-cve-2021-417731★ · 2022-12-05
- TheLastVvV/CVE-2021-417730★ · 2021-10-23
- TishcaTpx/POC-CVE-2021-417736★ · 2021-10-05
- Undefind404/cve_2021_417735★ · 2022-11-03
- Vanshuk-Bhagat/Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-420130★ · 2025-03-11
- Vulnmachines/cve-2021-4177338★ · 2022-08-30
- ZephrFish/CVE-2021-41773-PoC17★ · 2026-07-30
- Zh0ngS0n1337/CVE-2021-417730★ · 2022-04-14
- Zyx2440/Apache-HTTP-Server-2.4.50-RCE2★ · 2024-08-26
- abdullah89255/Manually-test-suspicious-findings0★ · 2025-08-18
- aqiao-jashell/CVE-2021-417739★ · 2025-08-15
- aqiao-jashell/py-CVE-2021-417737★ · 2022-11-02
- asaotomo/CVE-2021-42013-Apache-RCE-Poc-Exp10★ · 2021-12-24
- ashique-thaha/CVE-2021-41773-POC0★ · 2025-03-20
- b1tsec/CVE-2021-417730★ · 2021-10-08
- blackn0te/Apache-HTTP-Server-2.4.49-2.4.50-Path-Traversal-Remote-Code-Execution14★ · 2025-08-22
- blasty/CVE-2021-41773211★ · 2021-10-07
- blu3ming/PoC-CVE-2021-417730★ · 2025-07-02
- byteofandri/CVE-2021-417732★ · 2021-10-07
- byteofjoshua/CVE-2021-417732★ · 2021-10-07
- capdegarde/apache_path_traversal1★ · 2021-10-07
- ch4os443/CVE-2021-417730★ · 2021-10-14
- charanvoonna/CVE-2021-417731★ · 2025-08-20
- corelight/CVE-2021-417731★ · 2021-10-28
- creadpag/CVE-2021-41773-POC8★ · 2022-12-28
- dileepdkumar/LayarKacaSiber-CVE-2021-417730★ · 2025-12-07
- enciphers-team/cve-exploits0★ · 2026-04-22
- fnatalucci/CVE-2021-41773-RCE0★ · 2021-10-06
- gwill-b/apache_path_traversal1★ · 2021-10-07
- habibiefaried/CVE-2021-41773-PoC3★ · 2021-10-06
- iilegacyyii/PoC-CVE-2021-4177352★ · 2021-11-24
- inbug-team/CVE-2021-41773_CVE-2021-42013147★ · 2021-10-09
- iosifache/ApacheRCEEssay2★ · 2022-05-13
- itsecurityco/CVE-2021-4177312★ · 2022-10-07
- j4k0m/CVE-2021-4177313★ · 2021-10-05
- javaamo/CVE-2021-417730★ · 2025-03-19
- jbovet/CVE-2021-417734★ · 2021-10-06
- justakazh/mass_cve-2021-4177329★ · 2023-11-14
- khaidtraivch/CVE-2021-41773-Apache-2.4.49-0★ · 2025-04-14
- knqyf263/CVE-2021-417739★ · 2021-10-06
- kubota/POC-CVE-2021-417731★ · 2021-11-16
- kyutc/apachepatchy0★ · 2021-11-11
- lorddemon/CVE-2021-41773-PoC39★ · 2021-10-06
- luisdavidgarcia/WebFortress0★ · 2025-07-09
- luismede/apache2.4.49-exploit0★ · 2024-10-17
- lulaide/WebTree1★ · 2025-08-08
- lulaide/go-poc1★ · 2025-08-07
- luongchivi/CVE-2021-417730★ · 2025-03-28
- luongchivi/Preproduce-CVE-2021-417730★ · 2025-03-28
- m96dg/CVE-2021-41773-exercise0★ · 2022-01-30
- mah4nzfr/CVE-2021-417730★ · 2025-08-11
- masahiro331/CVE-2021-417731★ · 2021-10-06
- mauricelambert/CVE-2021-417731★ · 2022-03-14
- mightysai1997/CVE-2021-41773-L-0★ · 2022-09-15
- mightysai1997/CVE-2021-41773-PoC0★ · 2025-12-11
- mightysai1997/CVE-2021-41773-i-0★ · 2025-12-11
- mightysai1997/CVE-2021-41773.git10★ · 2022-09-15
- mightysai1997/CVE-2021-41773S1★ · 2025-12-08
- mightysai1997/CVE-2021-41773h0★ · 2026-01-09
- mightysai1997/CVE-2021-41773m1★ · 2022-09-15
- mightysai1997/cve-2021-417730★ · 2022-09-15
- mightysai1997/cve-2021-41773-v-0★ · 2022-09-15
- mmtalsi/toolbox0★ · 2025-06-22
- mohwahyudi/cve-2021-417730★ · 2021-10-08
- mr-exo/CVE-2021-4177311★ · 2021-10-26
- n3k00n3/CVE-2021-417731★ · 2021-10-08
- noflowpls/CVE-2021-417736★ · 2022-11-15
- norrig/CVE-2021-41773-exploiter0★ · 2022-01-13
- numanturle/CVE-2021-417738★ · 2021-10-05
- orangmuda/CVE-2021-417732★ · 2021-10-07
- pirenga/CVE-2021-417730★ · 2021-11-11
- pisut4152/Sigma-Rule-for-CVE-2021-41773-and-CVE-2021-42013-exploitation-attempt0★ · 2021-10-08
- puckiestyle/CVE-2021-417730★ · 2022-03-28
- pwn3z/CVE-2021-41773-Apache-RCE0★ · 2022-06-17
- r00tVen0m/CVE-2021-417731★ · 2021-10-06
- r0otk3r/CVE-2021-417730★ · 2025-07-12
- randomAnalyst/PoC-Fetcher0★ · 2022-07-23
- ranggaggngntt/CVE-2021-417730★ · 2022-06-11
- redspy-sec/CVE-2021-417730★ · 2024-12-16
- scarmandef/CVE-2021-417730★ · 2021-10-14
- sergiovks/LFI-RCE-Unauthenticated-Apache-2.4.49-2.4.505★ · 2023-06-13
- shellreaper/CVE-2021-417731★ · 2021-11-12
- shiomiyan/CVE-2021-417730★ · 2021-10-15
- sixpacksecurity/CVE-2021-417730★ · 2021-10-07
- skentagon/CVE-2021-417730★ · 2024-10-28
- superzerosec/CVE-2021-417733★ · 2021-10-11
- swaptt/swapt-it0★ · 2022-04-10
- thehackersbrain/CVE-2021-41773113★ · 2022-03-12
- tiemio/SSH-key-and-RCE-PoC-for-CVE-2021-417730★ · 2025-02-02
- twseptian/CVE-2021-417734★ · 2021-10-10
- vinhjaxt/CVE-2021-41773-exploit1★ · 2021-10-08
- vsfx1/apache_path_traversal1★ · 2021-10-07
- vulf/CVE-2021-41773_420131★ · 2021-10-18
- vuongnv3389-sec/cve-2021-417730★ · 2022-04-06
- walnutsecurity/cve-2021-417732★ · 2023-01-11
- wolf1892/CVE-2021-417730★ · 2021-10-29
- xMohamed0/CVE-2021-417730★ · 2021-11-14
- zer0qs/CVE-2021-417730★ · 2022-04-14
- zerodaywolf/CVE-2021-41773_420131★ · 2021-10-18
- zeronine9/CVE-2021-4177311★ · 2021-10-08
- abdulrafay25-svg/CVE-2021-41773-Exploit0★ · 2026-08-26
- Areeba-Zehra-Jafri/CVE-2021-41773---Apache-Path-Traversal---RCE
- AzkOsDev/CVE-2021-41773
- DappaNISM/mass_cve-2021-41773
- Emaar1x/CVE-2021-41773
- ISabbiI/PoC-Apache-CVE-2021-41773-Infrastructure-LAB
- JKIM72403/CS4277-CVE-Path-Traversal-Apache-HTTP-Server
- Joapath/CVE-2021-41773
- Nanxsec/exploitApache
- Park123r/CVE-2021-41773
- SANR01/CVE-2021-41773-Exploit-Lab
- Shams-Ul-Mehmood/CVE-2021-41773-Exploit
- a24ac1/CVE-2021-41773-PoC
- abds059/APACHE-PATH-TRAVERSAL-RCE-CVE-2021-41773-
- adrianmafandy/CVE-2021-41773
- dserdyk3-arch/Serdyuk-DO-homework-CVE-2021-41773
- fxdyx-a/CVE-2021-41773-POC
- gagaltotal/CVE-2021-41773-apache
- gunzf0x/CVE-2021-41773
- im2sinister/CVE-2021-41773
- johnwickakash12/CVE-2021-41773
- lheeeesoo/Apache-CVE-2021-41773
- sobanahmed6061/CVE-2021-41773-RedTeam
- sudo0xksh/cve-2021-41773-checker
- zubairahm3d/apache-cve-2021-41773-lab
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (2)
Vulhub environments (1)
Exploit collections (3)
- chaitin/xray/blob/master/pocs/apache-httpd-cve-2021-41773-rce.yml
- helloexp/0day/tree/master/03-Apache%20%26%20Tomcat/Apache/(CVE-2021-41773)%20Apache%20%E8…
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2021/CVE-2021-41773.yaml