Owasp Modsecurity Core Rule Set vulnerabilities

9 known vulnerabilities affecting owasp/owasp_modsecurity_core_rule_set.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-33691HIGHCVSS 7.5fixed in 3.3.9≥ 4.0.0, < 4.25.02026-04-02
CVE-2026-33691 [HIGH] CWE-178 CVE-2026-33691: The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.j
nvd
CVE-2026-21876MEDIUMCVSS 5.3fixed in 3.3.8≥ 4.0.0, < 4.22.02026-01-08
CVE-2026-21876 [MEDIUM] CWE-794 CVE-2026-21876: The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like `MULTIPART_PART_HEADERS`), the captur
nvd
CVE-2022-39956CRITICALCVSS 9.8≥ 3.0.0, < 3.2.2≥ 3.3.0, < 3.3.32022-09-20
CVE-2022-39956 [CRITICAL] CWE-863 CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipar The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and
nvd
CVE-2022-39955CRITICALCVSS 9.8≥ 3.0.0, < 3.2.2≥ 3.3.0, < 3.3.32022-09-20
CVE-2022-39955 [CRITICAL] CWE-863 CVE-2022-39955: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a s The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore bypassing the configurable CRS Co
nvd
CVE-2022-39957HIGHCVSS 7.5≥ 3.0.0, < 3.2.2≥ 3.3.0, < 3.3.32022-09-20
CVE-2022-39957 [HIGH] CWE-693 CVE-2022-39957: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to whi
nvd
CVE-2022-39958HIGHCVSS 7.5≥ 3.0.0, < 3.2.2≥ 3.3.0, < 3.3.32022-09-20
CVE-2022-39958 [HIGH] CWE-863 CVE-2022-39958: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfi The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily be detected, may be exfiltrated from the backend, despite being protected
nvd
CVE-2020-22669CRITICALCVSS 9.8v3.2.02022-09-02
CVE-2020-22669 [CRITICAL] CWE-89 CVE-2020-22669: Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerabi Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
nvd
CVE-2021-35368CRITICALCVSS 9.8≥ 3.1.0, < 3.1.2≥ 3.2.0, < 3.2.1+1 more2021-11-05
CVE-2021-35368 [CRITICAL] CVE-2021-35368: OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is af OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
nvd
CVE-2018-16384HIGHCVSS 7.5≤ 3.0.2v3.1.02018-09-03
CVE-2018-16384 [HIGH] CWE-89 CVE-2018-16384: A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
nvd
Owasp Modsecurity Core Rule Set vulnerabilities | cvebase