Critical severity9.8NVD Advisory· Published Dec 20, 2021· Updated Jun 17, 2026
CVE-2021-44790
CVE-2021-44790
Description
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
81cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: <2.4.52
- (no CPE)range: <=2.4.51
- (no CPE)range: Apache HTTP Server 2.4
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*Range: <=9.0
cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_operations_monitor:4.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_operations_monitor:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*Range: <=9.0
- cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*Range: <=9.0
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-004:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-005:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-006:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-007:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-008:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-003:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords46 versionspkg:bitnami/apachepkg:rpm/almalinux/httpdpkg:rpm/almalinux/httpd-develpkg:rpm/almalinux/httpd-filesystempkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/httpd-toolspkg:rpm/almalinux/mod_http2pkg:rpm/almalinux/mod_ldappkg:rpm/almalinux/mod_mdpkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/almalinux/mod_sessionpkg:rpm/almalinux/mod_sslpkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/apache2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/apache2&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/apache2&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP3
< 2.4.52+ 45 more
- (no CPE)range: < 2.4.52
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 1.15.7-3.module_el8.5.0+2609+b30d9eec
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 1:2.0.8-8.module_el8.5.0+2609+b30d9eec
- (no CPE)range: < 1:2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 1:2.4.37-43.module_el8.5.0+2609+b30d9eec.1.alma
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.52-1.1
- (no CPE)range: < 99.0.4844.84-bp153.2.75.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.51-3.37.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.51-35.7.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.51-35.7.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.33-3.61.1
- (no CPE)range: < 2.4.51-35.7.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 2.4.23-29.83.1
- (no CPE)range: < 99.0.4844.84-bp153.2.75.1
Patches
Vulnerability mechanics
References
20- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party Advisory
- packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.htmlnvdExploit
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- seclists.org/fulldisclosure/2022/May/33nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/May/35nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/May/38nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/12/20/4nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/nvdThird Party Advisory
- security.gentoo.org/glsa/202208-20nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20211224-0001/nvdThird Party Advisory
- support.apple.com/kb/HT213255nvdThird Party Advisory
- support.apple.com/kb/HT213256nvdThird Party Advisory
- support.apple.com/kb/HT213257nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5035nvdThird Party Advisory
- www.tenable.com/security/tns-2022-01nvdThird Party Advisory
- www.tenable.com/security/tns-2022-03nvdThird Party Advisory
News mentions
0No linked articles in our index yet.