Search CVE reports
1 – 10 of 15 results
[GHSA-2vqc-36qp-ccmw: Weak libcurl TLS hostname verification setting when fetching over HTTPS]
2 affected packages
modsecurity, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
| modsecurity-apache | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
[GHSA-cxqf-vgrr-xxrv: HTML decoder missing entities, leading to evasion]
2 affected packages
modsecurity, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
| modsecurity-apache | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 8 of 9
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The...
1 affected package
modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity-apache | Not affected | Fixed | Fixed | Fixed | Fixed |
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable...
2 affected packages
modsecurity, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity | Not affected | Not affected | Not affected | Not affected | — |
| modsecurity-apache | Not affected | Fixed | Fixed | Fixed | Fixed |
Some fixes available 4 of 5
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read...
1 affected package
modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity-apache | Not affected | Not affected | Fixed | Fixed | Fixed |
Some fixes available 5 of 9
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to...
2 affected packages
modsecurity, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity | Not affected | Not affected | Needs evaluation | Needs evaluation | Not in release |
| modsecurity-apache | Not affected | Not affected | Fixed | Fixed | Fixed |
Some fixes available 3 of 18
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large...
2 affected packages
modsecurity, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
| modsecurity-apache | Not affected | Not affected | Not affected | Fixed | Fixed |
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how...
2 affected packages
modsecurity, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity | — | Not affected | Not affected | Not affected | Not in release |
| modsecurity-apache | — | Not affected | Not affected | Not affected | Not affected |
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured
1 affected package
modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| modsecurity-apache | — | Not affected | Not affected | Not affected | Not affected |
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
2 affected packages
libapache-mod-security, modsecurity-apache
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libapache-mod-security | — | — | — | — | — |
| modsecurity-apache | — | — | — | — | — |