Back

MEDIUM

ModSecurity empty XML tag causes segmentation fault

Published Jul 2, 2025

Description

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty XML tag can cause a segmentation fault. If SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is application/xml, and at least one XML tag is empty (eg <foo></foo>), then a segmentation fault occurs. This issue has been patched in version 2.9.11. A workaround involves setting SecParseXmlIntoArgs to Off.

Affected products

Remediation

Red Hat mitigation

Users unable to upgrade may set `SecParseXmlIntoArgs` to `Off`

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 2, 2025
Updated Jul 2, 2025
Reserved Jun 20, 2025
CISA Vulnrichment
Updated Jul 2, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 2, 2025
ENISA EUVD
Assigner GitHub_M
Published Jul 2, 2025
Updated Jul 2, 2025
Exploited since n/a
EUVD-2025-19726