Browse all 6 CVE security advisories affecting owasp-modsecurity. AI-powered Chinese analysis, POCs, and references for each vulnerability.
OWASP ModSecurity serves as a web application firewall (WAF) that provides real-time website protection against attacks. It primarily defends against common vulnerability classes including remote code execution (RCE), cross-site scripting (XSS), SQL injection, and privilege escalation. The open-source solution has historically protected applications from OWASP Top 10 threats while allowing custom rule creation. With 6 CVEs recorded, ModSecurity maintains a strong security posture but has faced incidents like rule bypass vulnerabilities in earlier versions. Its core strength lies in its ability to inspect HTTP traffic and enforce security policies, making it a critical component for organizations seeking to protect web applications from exploitation without requiring application code modifications.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-30923 | libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings — ModSecurityCWE-125 | 7.5 | - | 2026-05-05 |
| CVE-2025-54571 | ModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure — ModSecurityCWE-252 | 6.1AI | MediumAI | 2025-08-05 |
| CVE-2025-52891 | ModSecurity empty XML tag causes segmentation fault — ModSecurityCWE-20 | 6.5 | Medium | 2025-07-02 |
| CVE-2025-48866 | ModSecurity has possible DoS vulnerability in sanitiseArg action — ModSecurityCWE-1050 | 7.5 | High | 2025-06-02 |
| CVE-2025-47947 | ModSecurity Has Possible DoS Vulnerability — ModSecurityCWE-1050 | 7.5 | High | 2025-05-21 |
| CVE-2025-27110 | Libmodsecurity3 has possible bypass of encoded HTML entities — ModSecurityCWE-172 | 5.3 | - | 2025-02-25 |
This page lists every published CVE security advisory associated with owasp-modsecurity. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.