Cyber Security News

Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests

OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions.

Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues.

The recently published advisory impacts ModSecurity’s version 3 engine, libmodsecurity3, and also affects some issues in the version 2 branch. Administrators should update to ModSecurity version 3.0.17 or version 2.9.15, depending on their deployment.

ModSecurity Vulnerabilities

The following vulnerabilities are identified by GitHub Security Advisory (GHSA) IDs rather than assigned CVEs:

AdvisorySeverityIssue
GHSA-5pww-8rfg-9crfHighRFC 2231 filename* multipart upload filename inspection bypass
GHSA-4j47-8qcr-jf59ModerateMalformed Base64 padding can bypass t:base64DecodeExt rule matching
GHSA-qrch-pjfr-9g47ModerateAdjacent comments bypass removeComments transformation
GHSA-5m93-4h75-3p2wModeratePCRE2 @rxGlobal match-limit errors handled as no-match
GHSA-jx3r-phvx-2jmjHighXML request body processor uninitialized pointer dereference
GHSA-vmg8-j66p-vgvwHighResponse-body inspection bypass via MIME-type case handling
GHSA-2vqc-36qp-ccmwLowIncorrect libcurl TLS hostname-verification configuration

ModSecurity has confirmed that some recent advisories lack CVE identifiers because they have not yet been assigned, not because the issues lack security impact.

GHSA-5pww-8rfg-9crf is a high-severity multipart parsing vulnerability that affects rules inspecting uploaded filenames. Vulnerable versions of ModSecurity only inspected the conventional filename field and did not account for RFC 2231’s extended filename* parameter.

An attacker could provide a benign filename for WAF inspection while using a different, potentially malicious filename through the filename* parameter.

Applications and frameworks that adhere to RFC-compliant parsing behavior, including Go, Python, Node.js, and Java backends, may process the attacker-controlled filename* value even if ModSecurity rules only evaluate the benign field.

This discrepancy can evade policies meant to block executable extensions, restricted file types, or suspicious upload names.

Several flaws also impact ModSecurity transformations and pattern matching. The t:removeComments vulnerability can allow adjacent comments to remain intact, which enables payload obfuscation and defeats signatures designed to normalize SQL or HTML comments.

Meanwhile, the t:base64DecodeExt issue can silently discard decoded content when processing malformed Base64 padding, causing a security rule to inspect an empty or incomplete value instead of the attacker’s original payload.

The PCRE2 @rxGlobal flaw is significant since certain match-limit errors are interpreted as a no-match result. Practically, this creates a fail-open scenario: a complex input that exhausts regular-expression matching limits may be treated as clean traffic rather than suspicious traffic.

Organizations are urged to upgrade promptly, review multipart upload rules, test Base64 and comment-obfuscation detections, and monitor the affected GHSA advisories for forthcoming CVE assignments.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

5 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

5 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

6 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

7 hours ago