Owasp

Modsecurity

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 05.08.2025 23:39:40
  • Last modified 06.08.2025 21:15:30

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP response’s Content-Type, which could lead to several issues depending on th...

Exploit
  • EPSS 0.3%
  • Published 02.06.2025 15:46:19
  • Last modified 02.07.2025 18:11:34

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `s...

  • EPSS 0.31%
  • Published 30.01.2024 16:15:47
  • Last modified 03.07.2025 20:59:18

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path ...

  • EPSS 0.31%
  • Published 26.07.2023 21:15:10
  • Last modified 03.07.2025 20:59:18

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

  • EPSS 0.06%
  • Published 28.04.2023 04:15:38
  • Last modified 03.07.2025 20:59:18

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.

  • EPSS 0.51%
  • Published 20.01.2023 19:15:17
  • Last modified 03.07.2025 20:59:18

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C l...

Exploit
  • EPSS 2.22%
  • Published 07.12.2021 22:15:06
  • Last modified 03.07.2025 20:59:18

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP ...

Exploit
  • EPSS 0.38%
  • Published 06.05.2021 17:15:07
  • Last modified 03.07.2025 20:59:18

ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.

Exploit
  • EPSS 3.79%
  • Published 06.10.2020 14:15:12
  • Last modified 03.07.2025 20:59:18

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles ...

  • EPSS 4.01%
  • Published 21.01.2020 22:15:15
  • Last modified 03.07.2025 20:59:18

Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeade...