À la une
Veille
Sécurité
DevOps
Cloud
IA
Self-hosted
Linux
Réseau
Rechercher
⌘K
EN
en direct
CVE-2025-15662 · CVSS 8.6
CVE-2025-50455 · CVSS 9.1
CVE-2025-59172 · CVSS 8.5
CVE-2025-68686 · Fortinet FortiOS
accueil
veille
Owasp
éditeur
Owasp
1
vulnérabilité suivie
10 juillet 2026
dernière publication
cve
Veille des vulnérabilités
identifiant
vulnérabilité
sévérité
publié
CVE-2026-52747
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16.
Owasp Modsecurity
Élevée
CVSS 8.6
10/07
← Retour à la veille
esc
Tapez au moins deux caractères.
↑
↓
naviguer
↵
ouvrir
esc
fermer