Back

HIGH

ModSecurity has possible DoS vulnerability in sanitiseArg action

Published Jun 2, 2025

Description

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.

Affected products

Remediation

Red Hat statement

User configuration must have at least one rule that does a `sanitiseMatchedBytes` action to be affected. Default configurations are not affected.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jun 2, 2025
Updated Jun 9, 2025
Reserved May 27, 2025

CISA Vulnrichment

Updated Jun 2, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jun 2, 2025
Bugzilla 2369827

ENISA EUVD

Assigner GitHub_M
Published Jun 2, 2025
Updated Jun 9, 2025

GitHub

No data