CVE-2021-44790 is a buffer overflow in the Apache HTTP Server mod_lua multipart request-body parser. A Lua script calling r:parsebody() can process a carefully crafted request body in a way that overflows a buffer. The issue affects Apache HTTP Server 2.4.51 and earlier.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This five-file repository is a standalone Python proof-of-concept and Docker-based local reproduction lab for CVE-2021-44790 in Apache HTTP Server mod_lua. The primary entry point, CVE-2021-44790.py, is a substantial Python 3 tool that parses a supplied HTTP/HTTPS target URL, tests connectivity, checks the apparent Apache version, constructs malformed multipart requests, and sends them over sockets. It exposes configurable boundary and body sizes, selectable data patterns (A/B, random, special characters, null bytes, and custom content), interactive operation, multithreaded request delivery, and fuzzing of boundary/payload sizes. Its practical capability is denial of service or crash testing; no instruction-pointer control, RCE chain, reverse shell, or post-exploitation payload is present. The cve-2021-44790-lab directory supplies a reproducible target. Its Dockerfile starts from httpd:2.4.51-bullseye, enables mod_lua, and installs Lua dependencies. httpd.conf listens on TCP port 80, maps /upload to lua/upload.lua, and sets LimitRequestBody 0. The Lua handler calls r:parsebody(), intentionally reaching the affected multipart parser, then prints parsed fields. README.md documents building the container and targeting http://127.0.0.1/upload. The repository is not associated with Metasploit, Nuclei, or another exploit framework.
This repository provides a proof-of-concept exploit for CVE-2021-44790, a buffer overflow vulnerability in the mod_lua module of Apache HTTP Server versions 2.4.51 and earlier. The exploit consists of a Python script (Request_Dac_Biet.py) that sends a specially crafted HTTP POST request with malformed multipart/form-data to a Lua handler endpoint (test.lua) hosted on a vulnerable Apache server. The Lua script (test.lua) simply calls r:parsebody(), which is the vulnerable function. The README.md provides detailed setup instructions, including configuring Apache with mod_lua and deploying the Lua script. The exploit is designed to cause a denial of service by crashing or restarting the Apache process when the buffer overflow is triggered. The repository targets both Windows and Linux platforms running the affected Apache versions. No weaponized or remote code execution payload is included; the exploit demonstrates the DoS condition.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A historical Apache mod_lua buffer-overflow vulnerability mentioned as background.
A critical vulnerability in Apache HTTP Server that can be exploited under certain misconfigurations or security settings.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.