logo

ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules

ID: 3aa5d28b-854d-5774-9afa-f8d8203953d5

STIX ID: report--3aa5d28b-854d-5774-9afa-f8d8203953d5

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-07-06

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

TL;DR: OWASP ModSecurity released v3.0.16 to fix two rule-bypass vulnerabilities in ModSecurity v3.0.15 and earlier — a high-severity multipart/form-data parser bug that removes embedded line breaks and can hide payloads from WAF rules (CVSS 8.6), and an i386-specific t:utf8toUnicode transformation error that can be evaded on 32-bit builds (CVSS 5.8). The advisory notes wide impact because ModSecurity is a commonly deployed WAF engine on Apache, Nginx, and IIS, reports no confirmed exploitation in the wild, and recommends immediate upgrade to 3.0.16, reviewing multipart rules, and avoiding i386 builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.