Owasp-Modsecurity / ModSecurity
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-52747 | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass | HIGH | 8.6 | Jul 10, 2026 |
| CVE-2026-52761 | ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture | MEDIUM | 5.8 | Jul 10, 2026 |
| CVE-2026-42268 | ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators | HIGH | 8.2 | May 12, 2026 |
| CVE-2026-30923 | libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings | HIGH | 8.2 | May 5, 2026 |
| CVE-2025-54571 | ModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure | MEDIUM | 6.9 | Aug 5, 2025 |
| CVE-2025-52891 | ModSecurity empty XML tag causes segmentation fault | MEDIUM | 6.5 | Jul 2, 2025 |
| CVE-2025-48866 | ModSecurity has possible DoS vulnerability in sanitiseArg action | HIGH | 7.5 | Jun 2, 2025 |
| CVE-2025-47947 | ModSecurity Has Possible DoS Vulnerability | HIGH | 7.5 | May 21, 2025 |
| CVE-2025-27110 | Libmodsecurity3 has possible bypass of encoded HTML entities | HIGH | 7.9 | Feb 25, 2025 |
| CVE-2024-1019 | WAF bypass of the ModSecurity v3 release line | HIGH | 8.6 | Jan 30, 2024 |
Showing 1 to 10 of 10 CVEs