CVE-2021-41773

ENISA EUVD: EUVD-2021-28781 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 9 articles Published: 2021-10-05

EPSS Score

Source: FIRST.org · 2026-05-23
94.43%
probability
This CVE has a 94.43% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.5
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2 (legacy)

4.3
MEDIUM
Access Vector
Network
Access Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
AV:N/AC:M/Au:N/C:P/I:N/A:N

Description

VulnerabilityLookup (CNA)
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

Affected Products

Apache Software Foundation
Apache HTTP Server
Apache HTTP Server 2.4 2.4.49

Attack Intelligence

Google Project Zero

Discovered
Sept. 29, 2021
Patched
Oct. 4, 2021
Reported by
Ash Daulton along with the cPanel Security Team
Root Cause Analysis
???

Exploits & PoC

blasty/CVE-2021-41773

CVE-2021-41773 playground

210 2021-10-07
inbug-team/CVE-2021-41773_CVE-2021-42013

CVE-2021-41773 CVE-2021-42013漏洞批量检测工具

147 2021-10-09
HightechSec/scarce-apache2

A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public

63 2021-10-07
MrCl0wnLab/SimplesApachePathTraversal

Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519

62 2024-08-14
Vulnmachines/cve-2021-41773

CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.

39 2022-08-30
29 2023-11-14
BlueTeamSteve/CVE-2021-41773

Vulnerable docker images for CVE-2021-41773

23 2021-10-06
im-hanzou/apachrot

Apache (Linux) CVE-2021-41773/2021-42013 Mass Vulnerability Checker

22 2021-10-12
Ls4ss/CVE-2021-41773_CVE-2021-42013

Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

20 2026-03-23
wangfly-me/Apache_Penetration_Tool

CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具

14 2023-05-22
j4k0m/CVE-2021-41773

Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.

13 2021-10-05
blackn0te/Apache-HTTP-Server-2.4.49-2.4.50-Path-Traversal-Remote-Code-Execution

Apache HTTP-Server 2.4.49-2.4.50 Path Traversal & Remote Code Execution PoC (CVE-2021-41773 & CVE-2021-42013)

13 2025-08-22
itsecurityco/CVE-2021-41773

CVE-2021-41773 POC with Docker

12 2022-10-07
Zeop-CyberSec/apache_normalize_path

Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)

12 2021-10-21
zeronine9/CVE-2021-41773

Fast python tool to test apache path traversal CVE-2021-41773 in a List of url

11 2021-10-08
mr-exo/CVE-2021-41773

Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50

11 2021-10-26
knqyf263/CVE-2021-41773

Path traversal in Apache HTTP Server 2.4.49 (CVE-2021-41773)

9 2021-10-06
1nhann/CVE-2021-41773

CVE-2021-41773 的复现

9 2021-10-08
theLSA/apache-httpd-path-traversal-checker

apache httpd path traversal checker(CVE-2021-41773 / CVE-2021-42013)

9 2021-10-16
aqiao-jashell/CVE-2021-41773

apache路径穿越漏洞poc&exp

9 2025-08-15
8 2021-10-05
8 2022-12-28
0xRar/CVE-2021-41773

Exploit for Apache 2.4.49

7 2021-10-08
aqiao-jashell/py-CVE-2021-41773

python编写的apache路径穿越poc&exp

7 2022-11-02
6 2021-10-05
6 2022-11-15
Hydragyrum/CVE-2021-41773-Playground

Some docker images to play with CVE-2021-41773 and CVE-2021-42013

6 2021-11-04
belajarqywok/CVE-2021-41773-MSF

Simple Metasploit-Framework module for conducting website penetration tests (CVE-2021-41773).

6 2023-08-11
jbovet/CVE-2021-41773

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 (CVE-2021-41773)

4 2021-10-06
twseptian/cve-2021-41773

CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited

4 2021-10-10
apapedulimu/Apachuk

CVE-2021-41773 Grabber

4 2021-10-11
LudovicPatho/CVE-2021-41773

The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.

4 2022-10-26
OfriOuzan/CVE-2021-41773_CVE-2021-42013_Exploits

Exploit CVE-2021-41773 and CVE-2021-42013

4 2023-08-02
RevShellXD/LFI-Destruction

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will s

4 2026-02-12
habibiefaried/CVE-2021-41773-PoC

PoC for CVE-2021-41773 with docker to demonstrate

3 2021-10-06
2 2021-10-20
jheeree/Simple-CVE-2021-41773-checker

Simple script realizado en bash, para revisión de múltiples hosts para CVE-2021-41773 (Apache)

2 2021-10-12
orangmuda/CVE-2021-41773

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

2 2021-10-07
5gstudent/cve-2021-41773-and-cve-2021-42013

cve-2021-41773 即 cve-2021-42013 批量检测脚本

2 2021-10-09
lopqto/CVE-2021-41773_Honeypot

Simple honeypot for CVE-2021-41773 vulnerability

2 2021-10-17
walnutsecurity/cve-2021-41773

cve-2021-41773.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.49

2 2023-01-11
Soliux/CVE-2021-41773

On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit serv

2 2021-11-11
iosifache/ApacheRCEEssay

Essay (and PoCs) about CVE-2021-41773, a remote code execution vulnerability in Apache 2.4.49 🕸️

2 2022-05-13
Habib0x0/CVE-2021-41773

CVE-2021-41773 | Apache HTTP Server 2.4.49 is vulnerable to Path Traversal and Remote Code execution attacks

2 2022-12-11
wvverez/CVE-2021-41773-PoC

「🪶」PoC (Proof of concept) of Path traversal + RCE in Apache HTTP Server 2.4.49

2 2026-05-20
PentesterGuruji/CVE-2021-41773

Path Traversal vulnerability in Apache 2.4.49

1 2021-10-07
n3k00n3/CVE-2021-41773

exploit to CVE-2021-41773

1 2021-10-08
vinhjaxt/CVE-2021-41773-exploit

CVE-2021-41773, poc, exploit

1 2021-10-08
shellreaper/CVE-2021-41773

This is a simple POC for Apache/2.4.49 Path Traversal Vulnerability

1 2021-11-12
corelight/CVE-2021-41773

A Zeek package which raises notices for Path Traversal/RCE in Apache HTTP Server 2.4.49 (CVE-2021-41773) and 2.4.50 (CVE-2021-42013)

1 2021-10-28
EagleTube/CVE-2021-41773

Apache 2.4.49 Path Traversal Vulnerability Checker

1 2021-10-09
ksanchezcld/httpd-2.4.49

critical: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) (CVE-2021-42013)

1 2021-10-12
zerodaywolf/CVE-2021-41773_42013

Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).

1 2021-10-18
IcmpOff/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit

This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If file

1 2021-11-09
TheKernelPanic/exploit-apache2-cve-2021-41773

Exploit for path transversal vulnerability in apache

1 2022-12-05
retrymp3/apache2.4.49VulnerableLabSetup

CVE-2021-41773 vulnerable apache version 2.4.49 lab set-up.

1 2023-02-18
Zyx2440/Apache-HTTP-Server-2.4.50-RCE

Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for e

1 2024-08-26
klmntbelgium/cve-2021-41773-exploration

Recreation and analysis of a curious logic error in Apache 2.4.49 that escalated to remote code execution

1 2026-04-27
TAI-REx/cve-2021-41773-nse

CVE-2021-41773.nse

0 2021-10-06
sixpacksecurity/CVE-2021-41773

CVE-2021-41773 exploit PoC with Docker setup.

0 2021-10-07
b1tsec/CVE-2021-41773

A Python script to check if an Apache web server is vulnerable to CVE-2021-41773

0 2021-10-08
ch4os443/CVE-2021-41773

Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

0 2021-10-14
twseptian/cve-2021-41773-docker-lab

Docker container lab to play/learn with CVE-2021-41773

0 2021-11-22
TheLastVvV/CVE-2021-41773

Poc CVE-2021-41773 - Apache 2.4.49 with CGI enabled

0 2021-10-23
vida003/Scanner-CVE-2021-41773

A automatic scanner to apache 2.4.49

0 2021-10-25
wolf1892/CVE-2021-41773

Setup vulnerable enviornment

0 2021-10-29
pirenga/CVE-2021-41773

Ce programme permet de détecter une faille RCE sur les serveurs Apache 2.4.49 et Apache 2.4.50

0 2021-11-11
bernardas/netsec-polygon

Environment for CVE-2021-41773 recreation.

0 2022-05-17
anldori/CVE-2021-41773-Scanner

CVE-2021-41773 Shodan scanner

0 2022-05-12
pwn3z/CVE-2021-41773-Apache-RCE

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fil

0 2022-06-17
EkamSinghWalia/Mitigation-Apache-CVE-2021-41773-

Mitigation/fix of CVE-2021-41773 A Path Traversal And File Disclosure Vulnerability In Apache

0 2022-07-22
12345qwert123456/CVE-2021-41773

Vulnerable configuration Apache HTTP Server version 2.4.49

0 2022-11-21
MatanelGordon/docker-cve-2021-41773

A little demonstration of cve-2021-41773 on httpd docker containers

0 2023-04-21
0xGabe/Apache-CVEs

Exploit created in python3 to exploit known vulnerabilities in Apache web server (CVE-2021-41773, CVE-2021-42013)

0 2023-06-03
0 2024-06-03
0xc4t/CVE-2021-41773

POC & Lab For CVE-2021-41773

0 2024-08-27
jkska23/Additive-Vulnerability-Analysis-CVE-2021-41773

Apache: a Mainstream Web Service Turned a Vector of Attack for Remote Code Execution

0 2024-08-28
0 2025-01-03
tiemio/SSH-key-and-RCE-PoC-for-CVE-2021-41773

This repository contains a Proof-of-Concept for the CVE-2021-41773. This CVE contains a LFI and RCE vulnerablity.

0 2025-02-02
Vanshuk-Bhagat/Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-42013

In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and CVE

0 2025-03-11
0 2025-03-19
ashique-thaha/CVE-2021-41773-POC

The POC and Lab setup documentation of CVE 2021 41773

0 2025-03-20
0 2025-04-14
psibot/apache-vulnerable

Detects Apache HTTP Server path traversal vulnerabilities (CVE-2021-41773, CVE-2021-42013) by checking for exposure of /etc/passwd through var

0 2025-07-01
blu3ming/PoC-CVE-2021-41773

Python exploit for CVE-2021-41773 - Apache HTTP Server 2.4.49 Path Traversal vulnerability

0 2025-07-02
mah4nzfr/CVE-2021-41773

Bash POC script for RCE vulnerability in Apache 2.4.49

0 2025-08-11
hackedrishi/CTF_WRITEUPS-TryHackMe-CVE-2021-41773-

CTF_WRITEUPS/TryHackMe /CVE-2021-41773/

0 2025-08-31
MuhammadHuzaifaAsif/security-lab

Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to

0 2025-09-14
gunzf0x/CVE-2021-41773

Remote Code Execution PoC for Apache 2.4.49

0 2025-10-07
faizdotid/CVE-2021-41773

Path Traversal Apache HTTP Server 2.4.49/2.4.50

0 2025-11-26
ChanaPCN/CVE-2021-41773-Analysis

Technical analysis and reproduction lab for the Apache HTTP Server 2.4.49 Path Traversal and RCE vulnerability.

0 2026-01-12
sudo0xksh/cve-2021-41773-checker

A simple Python proof-of-concept tool to check for Apache path traversal vulnerability (CVE-2021-41773). Detects vulnerable server versions and verif

0 2026-01-16
dserdyk3-arch/Serdyuk-DO-homework-CVE-2021-41773

PoC скрипт для CVE-2021-41773 - Path Traversal в Apache 2.4.49

0 2026-02-07
Nanxsec/exploitApache

exploit para a CVE-2021-41773:Path Traversal cgi-bin

0 2026-03-15
zubairahm3d/apache-cve-2021-41773-lab

Vulnerable Docker lab and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE‑2021‑41773)

0 2026-03-16
tsiddiquea/cve-reproduction-lab

Cybersecurity lab demonstrating Apache CVE-2021-41773 path traversal vulnerability with vulnerable server simulation, scanner, and security reporting.

0 2026-03-18
sobanahmed6061/CVE-2021-41773-RedTeam

Apache 2.4.49 Path Traversal RCE

0 2026-03-18
JKIM72403/CS4277-CVE-Path-Traversal-Apache-HTTP-Server

We hope to reproduce CVE-2021-41773 to deepen our understanding of real-world cybersecurity vulnerabilities so that we can be knowledgeable about expl

0 2026-04-28
143 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 94.43%
CVSS v3.1 7.5
Mentions 9
Last Seen Oct 07, 2022

CNA Information

CNA Assigner
apache
CNA Title
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

Analyst Note

CVE-2021-41773 is a well-documented path traversal vulnerability in Apache HTTP Server 2.4.49 with a HIGH CVSS score of 7.5, confirmed by Google Project Zero and documented in official CERT-EU security advisories. The vulnerability's impact on URL-to-file mapping outside configured directories with potential CGI execution makes it a confirmed, high-severity issue with clear exploitation pathways.

Threat Actors 6

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cron
apt_group 🇷🇺 RU
Kinsing
apt_group 🇷🇺 RU
TeamTNT
apt_group 🇩🇪 DE
Red October
apt_group 🇷🇺 RU
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026
Published DateOct 05, 2021