VYPR
High severity7.5NVD Advisory· Published Oct 5, 2021· Updated Jun 17, 2026

CVE-2021-41524

CVE-2021-41524

Description

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Apache/Httpdllm-fuzzy
    Range: <2.4.49
  • Apache/HTTP Servercpe-rescue2 versions
    2.4.49+ 1 more
    • (no CPE)range: 2.4.49
    • cpe:2.3:a:apache:http_server:2.4.49:*:*:*:*:*:*:*
  • osv-coords
    Range: >= 2.4.49, < 2.4.50
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.