Search CVE reports


Toggle filters

1 – 10 of 36 results


CVE-2025-54571

Medium priority
Needs evaluation

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP response’s Content-Type, which could lead to several...

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-52891

Medium priority
Needs evaluation

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty XML tag can cause a segmentation fault. If SecParseXmlIntoArgs is set to...

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-48866

Medium priority

Some fixes available 8 of 9

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The...

1 affected package

modsecurity-apache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity-apache Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-47947

Medium priority
Fixed

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable...

2 affected packages

modsecurity, modsecurity-apache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Not affected Not affected Not affected
modsecurity-apache Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-27110

Medium priority
Needs evaluation

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in...

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-46292

Medium priority
Needs evaluation

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the...

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-1019

Medium priority
Needs evaluation

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it...

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2023-38285

Medium priority
Needs evaluation

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2023-38199

Medium priority
Needs evaluation

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka...

1 affected package

modsecurity-crs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity-crs Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-28882

Medium priority
Needs evaluation

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.

1 affected package

modsecurity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages