| Bug | bookworm | trixie | forky | sid | Description |
|---|
| TEMP-1149651-E1250D | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-4j47-8qcr-jf59: t:base64DecodeExt does not decode - and _, bypassing rules on URL-safe encoded payloads |
| TEMP-1149651-879765 | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-qrch-pjfr-9g47: t:removeComments mishandles the character after a comment terminator, bypassing rules |
| TEMP-1149651-638CCA | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-5m93-4h75-3p2w: @rxGlobal PCRE2 error handling: match-limit fail-open and invalid-pattern crash |
| TEMP-1149651-340E45 | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-5pww-8rfg-9crf: RFC 2231 filename* parameter bypasses multipart filename rules |
| CVE-2026-73857 | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-jx3r-phvx-2jmj: XML request body processor dereferences an uninitialized parser context pointer |
| CVE-2026-73856 | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-vmg8-j66p-vgvw: Response body inspection bypass via non-canonical Content-Type casing |
| CVE-2026-61813 | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-2vqc-36qp-ccmw: Weak libcurl TLS hostname verification setting when fetching over HTTPS |
| CVE-2026-61812 | vulnerable | vulnerable | vulnerable | vulnerable | GHSA-cxqf-vgrr-xxrv: HTML decoder missing entities, leading to evasion |
| CVE-2026-52761 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | ModSecurity is an open source, cross platform web application firewall ... |
| CVE-2026-52747 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | ModSecurity is an open source, cross platform web application firewall ... |
| CVE-2024-1019 | vulnerable (no DSA) | fixed | fixed | fixed | ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypa ... |
| Bug | Description |
|---|
| CVE-2026-42268 | ModSecurity is an open source, cross platform web application firewall ... |
| CVE-2026-30923 | ModSecurity is an open source, cross platform web application firewall ... |
| CVE-2025-27110 | Libmodsecurity is one component of the ModSecurity v3 project. The lib ... |
| CVE-2023-38285 | Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Co ... |
| CVE-2023-28882 | Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial ... |
| CVE-2022-48279 | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart reque ... |
| CVE-2021-42717 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objec ... |
| CVE-2020-15598 | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a ... |
| CVE-2019-25043 | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as dem ... |
| CVE-2019-19886 | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send c ... |