logo

OWASP CRS Vulnerability Enables Charset Validation Bypass 

ID: 9528af30-b78d-5455-9470-45b80b63914a

STIX ID: report--9528af30-b78d-5455-9470-45b80b63914a

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Divya

...
...

A critical vulnerability (CVE-2026-21876) in OWASP CRS rule 922110 enables a charset validation bypass for multipart/form-data requests—allowing UTF-7 and other non-whitelisted encodings (e.g., UTF-16, Shift-JIS) to reach backend apps and potentially enable XSS—affecting CRS 3.3.x and 4.0.0–4.21.0 across ModSecurity and Coraza; fixes are released in CRS 4.22.0 and 3.3.8 and administrators are advised to upgrade immediately and review historical multipart request logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.