Owasp / Modsecurity
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-52747 | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass | HIGH | 8.6 | Jul 10, 2026 |
| CVE-2026-52761 | ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture | MEDIUM | 5.8 | Jul 10, 2026 |
| CVE-2026-42268 | ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators | HIGH | 8.2 | May 12, 2026 |
| CVE-2026-30923 | libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings | HIGH | 8.2 | May 5, 2026 |
| CVE-2025-54571 | ModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure | MEDIUM | 6.9 | Aug 5, 2025 |
| CVE-2025-48866 | ModSecurity has possible DoS vulnerability in sanitiseArg action | HIGH | 7.5 | Jun 2, 2025 |
| CVE-2024-1019 | WAF bypass of the ModSecurity v3 release line | HIGH | 8.6 | Jan 30, 2024 |
| CVE-2023-38285 | mod_security: DoS Vulnerability in Four Transformations | HIGH | 7.5 | Jul 26, 2023 |
| CVE-2023-28882 | mod_security: a segfault and a resultant crash of a worker process in some configurations with certain inputs | HIGH | 7.5 | Apr 28, 2023 |
| CVE-2022-48279 | mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass | HIGH | 7.5 | Jan 20, 2023 |
| CVE-2021-42717 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web serv… | HIGH | 7.5 | Dec 7, 2021 |
| CVE-2019-25043 | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie:… | MEDIUM | 5.3 | May 6, 2021 |
| CVE-2020-15598 | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing… | HIGH | 7.5 | Oct 6, 2020 |
| CVE-2019-19886 | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming… | HIGH | 7.5 | Jan 21, 2020 |
| CVE-2018-13065 | ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments wit… | MEDIUM | 6.1 | Jul 3, 2018 |
Showing 1 to 15 of 15 CVEs