CVE-2021-30641
published 2021-06-10CVE-2021-30641: Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
PriorityP343medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
52.33%
98.8th percentile
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.4.39 – 2.4.46 | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| debian | apache2 | < apache2 2.4.46-6 (bookworm) | apache2 2.4.46-6 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_httpd_2.4.46-10_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_httpd_2.4.46-5_on_cbl_mariner_1.0 | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability affects Apache HTTP Server versions 2.4.39 through 2.4.46 when the MergeSlashes directive is involved; monitor for unexpected URL matching behavior on servers running these versions with MergeSlashes configured. ↗
- →The flaw was introduced as a regression from the fix for CVE-2019-0220; systems patched for that CVE in the affected version range are likely vulnerable and should be prioritized for detection/patching. ↗
- →The upstream Apache bug report and patch commit can be used to diff behavior and build regression tests: review commit eb986059aa5aa0b6c1d52714ea83e3dd758afdd1 in the Apache httpd repository for the exact code change. ↗
- ·Setting 'MergeSlashes OFF' is cited as a mitigation, but the vulnerability is specifically about unexpected behavior when this directive is used — verify that toggling this directive does not introduce other routing/security issues in the specific deployment. ↗
- ·The highest threat from this vulnerability is to data integrity (not confidentiality or availability), meaning access controls or routing rules relying on URL normalization may be silently bypassed. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jfgv-4796-2jw7: Apache HTTP Server versions 2
ghsa_unreviewed·2022-05-24
CVE-2021-30641 [MEDIUM] GHSA-jfgv-4796-2jw7: Apache HTTP Server versions 2
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
OSV
apache2 vulnerabilities
osv·2021-06-21·CVSS 7.3
CVE-2020-35452 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-4994-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue to cause Apache to crash, resulting in a denial of service.
(CVE-2021-26690)
Christophe Jaillet discovered that the Apache mod_session module
incorrectly handled certain SessionHeader values. A remote attacker could
OSV
apache2 vulnerabilities
osv·2021-06-21·CVSS 7.5
CVE-2020-13950 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
Marc Stern discovered that the Apache mod_proxy_http module incorrectly
handled certain requests. A remote attacker could possibly use this issue
to cause Apache to crash, resulting in a denial of service. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2020-13950)
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue to cause Apache to crash, resulting in a denial of service.
(CVE-2021-26690)
Christoph
OSV
CVE-2021-30641: Apache HTTP Server versions 2
osv·2021-06-10·CVSS 5.3
CVE-2021-30641 [MEDIUM] CVE-2021-30641: Apache HTTP Server versions 2
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-06-21·CVSS 7.5
CVE-2021-26691 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Marc Stern discovered that the Apache mod_proxy_http module incorrectly
handled certain requests. A remote attacker could possibly use this issue
to cause Apache to crash, resulting in a denial of service. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2020-13950)
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue t
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-06-21·CVSS 7.3
CVE-2021-26691 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-4994-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue to cause Apache to crash, resulting in a denial of service.
(CVE-2021-26690)
Christophe Jaillet discovered that the Apache mod_se
Microsoft
Unexpected URL matching with 'MergeSlashes OFF'
vendor_msrc·2021-06-08·CVSS 5.3
CVE-2021-30641 [MEDIUM] Unexpected URL matching with 'MergeSlashes OFF'
Unexpected URL matching with 'MergeSlashes OFF'
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micro
Red Hat
httpd: Unexpected URL matching with 'MergeSlashes OFF'
vendor_redhat·2021-06-04·CVSS 5.3
CVE-2021-30641 [MEDIUM] CWE-20 httpd: Unexpected URL matching with 'MergeSlashes OFF'
httpd: Unexpected URL matching with 'MergeSlashes OFF'
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
A flaw was found in Apache httpd. A possible regression from an earlier security fix broke behavior of MergeSlashes. The highest threat from this vulnerability is to data integrity.
Statement: This flaw was introduced when fixing https://access.redhat.com/security/cve/cve-2019-0220, therefore versions of httpd package shipped with Red Hat Enterprise Linux 7, 8 and Red Hat Software Collections are affected by this flaw.
Mitigation: This issue can be mitigated by setting the "MergeSlashes" directive to OFF
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Out of support scope
Pack
Debian
CVE-2021-30641: apache2 - Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with '...
vendor_debian·2021·CVSS 5.3
CVE-2021-30641 [MEDIUM] CVE-2021-30641: apache2 - Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with '...
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
Scope: local
bookworm: resolved (fixed in 2.4.46-6)
bullseye: resolved (fixed in 2.4.46-6)
forky: resolved (fixed in 2.4.46-6)
sid: resolved (fixed in 2.4.46-6)
trixie: resolved (fixed in 2.4.46-6)
No detection rules found.
No public exploits indexed.
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/8https://lists.apache.org/thread.html/r2b4773944d83d2799de9fbaeee7fe0f3fd72669467787e02f434cb10%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/https://security.gentoo.org/glsa/202107-38https://security.netapp.com/advisory/ntap-20210702-0001/https://www.debian.org/security/2021/dsa-4937https://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/8https://lists.apache.org/thread.html/r2b4773944d83d2799de9fbaeee7fe0f3fd72669467787e02f434cb10%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/https://security.gentoo.org/glsa/202107-38https://security.netapp.com/advisory/ntap-20210702-0001/https://www.debian.org/security/2021/dsa-4937https://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-10
Published