OWASP CRS Vulnerability Enables Charset Validation Bypass
ID: 9528af30-b78d-5455-9470-45b80b63914a
STIX ID: report--9528af30-b78d-5455-9470-45b80b63914a
Feed Name: GBHackers
Threat Score
A critical vulnerability (CVE-2026-21876) in OWASP CRS rule 922110 enables a charset validation bypass for multipart/form-data requests—allowing UTF-7 and other non-whitelisted encodings (e.g., UTF-16, Shift-JIS) to reach backend apps and potentially enable XSS—affecting CRS 3.3.x and 4.0.0–4.21.0 across ModSecurity and Coraza; fixes are released in CRS 4.22.0 and 3.3.8 and administrators are advised to upgrade immediately and review historical multipart request logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
