Debian Modsecurity-Crs vulnerabilities
16 known vulnerabilities affecting debian/modsecurity-crs.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH4MEDIUM1LOW7
Vulnerabilities
Page 1 of 1
CVE-2026-21876CRITICALCVSS 9.3fixed in modsecurity-crs 3.3.4-1+deb12u1 (bookworm)2026
CVE-2026-21876 [CRITICAL] CVE-2026-21876: modsecurity-crs - The OWASP core rule set (CRS) is a set of generic attack detection rules for use...
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like `MULTIPART_PART_HEADERS`), the capture var
debian
CVE-2026-33691MEDIUMCVSS 6.8fixed in modsecurity-crs 3.3.9-1 (forky)2026
CVE-2026-33691 [MEDIUM] CVE-2026-33691: modsecurity-crs - The OWASP core rule set (CRS) is a set of generic attack detection rules for use...
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ).
debian
CVE-2023-38199CRITICALCVSS 9.8fixed in modsecurity-crs 3.3.4-1~deb11u2 (bullseye)2023
CVE-2023-38199 [CRITICAL] CVE-2023-38199: modsecurity-crs - coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect ...
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka "Content-Type confusion" between the WAF and the backend application. This occurs when the web application relies on only the last Content-Type head
debian
CVE-2022-39957HIGHCVSS 7.3fixed in modsecurity-crs 3.3.4-1 (bookworm)2022
CVE-2022-39957 [HIGH] CVE-2022-39957: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass....
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which wou
debian
CVE-2022-39955HIGHCVSS 7.3fixed in modsecurity-crs 3.3.4-1 (bookworm)2022
CVE-2022-39955 [HIGH] CVE-2022-39955: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypa...
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore bypassing the configurable CRS Content-Type
debian
CVE-2022-39958HIGHCVSS 7.5fixed in modsecurity-crs 3.3.4-1 (bookworm)2022
CVE-2022-39958 [HIGH] CVE-2022-39958: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass ...
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily be detected, may be exfiltrated from the backend, despite being protected by a w
debian
CVE-2022-39956HIGHCVSS 7.3fixed in modsecurity-crs 3.3.4-1 (bookworm)2022
CVE-2022-39956 [HIGH] CVE-2022-39956: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypa...
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule se
debian
CVE-2021-35368CRITICALCVSS 9.8fixed in modsecurity-crs 3.3.2-1 (bookworm)2021
CVE-2021-35368 [CRITICAL] CVE-2021-35368: modsecurity-crs - OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3....
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
Scope: local
bookworm: resolved (fixed in 3.3.2-1)
bullseye: resolved (fixed in 3.3.0-1+deb11u1)
forky: resolved (fixed in 3.3.2-1)
sid: resolved (fixed in 3.3.2-1)
trixie: resolved (fixed in 3.3.2-1
debian
CVE-2020-22669CRITICALCVSS 9.8fixed in modsecurity-crs 3.3.2-1 (bookworm)2020
CVE-2020-22669 [CRITICAL] CVE-2020-22669: modsecurity-crs - Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL inject...
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Scope: local
bookworm: resolved (fixed in 3.3.2-1)
bullseye: resolved (f
debian
CVE-2019-13464LOWCVSS 7.5fixed in modsecurity-crs 3.2.0-1 (bookworm)2019
CVE-2019-13464 [HIGH] CVE-2019-13464: modsecurity-crs - An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X...
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
bullseye: resolved (fixed in 3.2.0-1)
forky: resolve
debian
CVE-2019-11388LOWCVSS 5.3fixed in modsecurity-crs 3.2.0-1 (bookworm)2019
CVE-2019-11388 [MEDIUM] CVE-2019-11388: modsecurity-crs - An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. ...
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with nested repetition operators. NOTE: the software maintainer disputes that this is a vulnerability because the issue cannot be e
debian
CVE-2019-11390LOWCVSS 5.32019
CVE-2019-11390 [MEDIUM] CVE-2019-11390: modsecurity-crs - An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. ...
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with set_error_handler# at the beginning and nested repetition operators. NOTE: the software maintainer disputes that this is a vul
debian
CVE-2019-11387LOWCVSS 5.3fixed in modsecurity-crs 3.1.1-1 (bookworm)2019
CVE-2019-11387 [MEDIUM] CVE-2019-11387: modsecurity-crs - An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. ...
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with nested repetition operators.
Scope: local
bookworm: resolved (fixed in 3.1.1-1)
bullseye: resolved (fixed in 3.1.1-1)
forky:
debian
CVE-2019-11391LOWCVSS 5.32019
CVE-2019-11391 [MEDIUM] CVE-2019-11391: modsecurity-crs - An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. ...
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with $a# at the beginning and nested repetition operators. NOTE: the software maintainer disputes that this is a vulnerability beca
debian
CVE-2019-11389LOWCVSS 5.32019
CVE-2019-11389 [MEDIUM] CVE-2019-11389: modsecurity-crs - An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. ...
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with next# at the beginning and nested repetition operators. NOTE: the software maintainer disputes that this is a vulnerability be
debian
CVE-2018-16384LOWCVSS 7.5fixed in modsecurity-crs 3.2.0-1 (bookworm)2018
CVE-2018-16384 [HIGH] CVE-2018-16384: modsecurity-crs - A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Se...
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
bullseye: resolved (fixed in 3.2.0-1)
forky: resolved (fixed in 3.2.0-1)
sid: re
debian