Search CVE reports


Toggle filters

1 – 10 of 15 results


CVE-2026-61813

Medium priority
Needs evaluation

[GHSA-2vqc-36qp-ccmw: Weak libcurl TLS hostname verification setting when fetching over HTTPS]

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
modsecurity-apache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-61812

Medium priority
Needs evaluation

[GHSA-cxqf-vgrr-xxrv: HTML decoder missing entities, leading to evasion]

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
modsecurity-apache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-48866

Medium priority

Some fixes available 8 of 9

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The...

1 affected package

modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity-apache Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-47947

Medium priority
Fixed

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable...

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Not affected Not affected Not affected Not affected —
modsecurity-apache Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-24021

Medium priority

Some fixes available 4 of 5

Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read...

1 affected package

modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity-apache Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-48279

Medium priority

Some fixes available 5 of 9

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to...

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Not affected Not affected Needs evaluation Needs evaluation Not in release
modsecurity-apache Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-42717

Medium priority

Some fixes available 3 of 18

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large...

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
modsecurity-apache Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-15598

Medium priority
Ignored

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how...

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity — Not affected Not affected Not affected Not in release
modsecurity-apache — Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-13065

Low priority
Ignored

ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured

1 affected package

modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity-apache — Not affected Not affected Not affected Not affected
Show less packages

CVE-2013-5705

Medium priority
Ignored

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

2 affected packages

libapache-mod-security, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-mod-security — — — — —
modsecurity-apache — — — — —
Show less packages