← Vulnerability feed

Vulnerability record · CVE-2021-42342 · published 14 October 2021

CVE-2021-42342: GoAhead file upload filter allows environment variable injection into CGI scripts

Embedthis · Goahead

GoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment variables reach CGI scripts. This breaks the boundary between user input and the CGI environment, so any CGI script that trusts those variables can be manipulated. The flaw is remotely reachable and rated critical by CVSS.

9.8 CVSS 3.1 Critical EPSS 59% · top 0.9% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a very high EPSS score, makes this a top remediation target despite no KEV listing.

What it is

GoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment variables reach CGI scripts. This breaks the boundary between user input and the CGI environment, so any CGI script that trusts those variables can be manipulated. The flaw is remotely reachable and rated critical by CVSS.

Impact

An attacker can inject arbitrary environment variables into CGI scripts, which can lead to code execution or full compromise of the web server process depending on what the CGI scripts do with those variables. The CVSS vector indicates high confidentiality, integrity and availability impact.

Attack surface

Reached over the network through the file upload filter; the CVSS vector shows no privileges and no user interaction required. Any deployment exposing GoAhead with CGI scripts is potentially in scope.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is 0.5946 (99th percentile), indicating a high likelihood of exploitation activity.

What to do

  • Upgrade GoAhead to 5.1.5 or later, which fixes the file upload filter prefix handling.
  • If immediate upgrade is not possible, disable or restrict the file upload filter and CGI script execution on internet-facing instances.
  • Audit CGI scripts for reliance on environment variables and validate or ignore unexpected variables.
  • Place GoAhead behind a reverse proxy or WAF that filters multipart uploads and suspicious form field names.
  • Monitor vendor advisories for backports if you run an embedded GoAhead build.

Detection

  • Inspect HTTP multipart upload requests for form field names that do not carry the expected CGI prefix.
  • Monitor CGI process environments for unexpected or attacker-controlled variable names.
  • Review web server logs for anomalous upload requests followed by CGI execution or error spikes.
  • Alert on GoAhead versions below 5.1.5 in asset inventories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42342 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-17562Embedthis GoAhead CGI environment variable injection enables remote code executionEmbedthis GoAhead before 3.6.5 initializes the environment of forked CGI scripts using untrusted HTTP request parameters in cgiHandler in cgi.c. When…KEVEPSS 96%analysed9.8CVE-2021-41615Embedthis goahead vulnerabilitywebsda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise valu…EPSS 1.4%9.8CVE-2021-43298Embedthis goahead improper restriction of authentication attempts vulnerabilityThe code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This me…EPSS 2.3%9.8CVE-2019-5096GoAhead web server use-after-free in multipart/form-data handlingGoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap s…EPSS 67%analysed9.8CVE-2017-1000471Embedthis goahead null pointer dereference vulnerabilityEmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of …EPSS 8.6%9.8CVE-2017-5674Embedthis goahead information exposure vulnerabilityA vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …EPSS 22%8.8CVE-2020-15688Embedthis goahead authentication bypass by capture-replay vulnerabilityThe HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthentica…EPSS 4.0%8.8CVE-2017-5675Embedthis goahead command injection vulnerabilityA command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2021-42342), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.