| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-42268 | vulnerable | vulnerable | vulnerable | vulnerable | fixed | Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators |
| CVE-2026-30923 | vulnerable | vulnerable | vulnerable | vulnerable | fixed | ModSecurity is an open source, cross platform web application firewall ... |
| CVE-2024-1019 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fixed | ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypa ... |
| CVE-2023-38285 | vulnerable (no DSA, ignored) | fixed | fixed | fixed | fixed | Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Co ... |
| CVE-2022-48279 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart reque ... |
| CVE-2021-42717 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objec ... |