Reads /etc/passwd through a double-encoded dot sequence. Apache 2.4.50 stopped the single-encoded form and still accepted this one.
Is your app exploitable through CVE-2021-42013?