boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2021-41773

Apache Software Foundation Apache HTTP Server — Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .9999   100.0   YES
AFFECTED
  Product             Versions                         Fixed
  Apache HTTP Server  Apache HTTP Server 2.4 2.4.49 –  —
TIMELINE
  Sep 29  Reserved by apache
  Oct 5   Published (CNA: apache)
  Nov 3   Added to CISA KEV, remediation due 2021-11-17
CWE-22 · CNA: apache · CVSS v3.1 · 30 references · KEV due November 17, 2021

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 29, 2021ReservedReserved by apache
October 5, 2021PublishedPublished (CNA: apache)
November 3, 2021KEV ADDEDAdded to CISA KEV, remediation due 2021-11-17

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache HTTP Server—Apache HTTP Server 2.4 2.4.49—

Weaknesses

CWE-22

References (30)

Related

Authoritative record: CVE-2021-41773 at cve.org

Vendors: apache

Weaknesses: CWE-22

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-41773 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.