HomeSecurityCritical vulnerabilities in ModSecurity - Experts recommend immediate upgrade

Critical vulnerabilities in ModSecurity – Experts recommend immediate upgrade

Significant security issues have been identified in OWASP ModSecurity, one of the most widely used open source Web Application Firewalls (WAFs), which is used by thousands of organizations to protect websites and web applications from attacks such as SQL Injection, Cross-Site Scripting (XSS) and other known threats.

ModSecurity

The two new vulnerabilities, listed as CVE-2026-52761 and CVE-2026-52747, affect all versions of ModSecurity up to and including 3.0.15. The fixes have already been incorporated into version 3.0.16, with experts urging system administrators to upgrade immediately.

Although both bugs differ in nature, they have one thing in common: they can allow malicious requests to bypass the WAF's control mechanisms, significantly reducing the effectiveness of protection.

Unicode conversion problem on 32-bit systems

The first vulnerability (CVE-2026-52761) concerns the utf8toUnicode, which is used by ModSecurity to normalize data before it is examined by security rules. Due to incorrect use of the sizeof() operator on a pointer type, the conversion produces truncated or incorrect results on 32-bit architectures.

See also: Opera GX: Critical vulnerability allowed silent installation of mods

In practice, this means that instead of processing the entire input content, ModSecurity only parses four bytes of data. As a result, Unicode conversion can be completed incorrectly, allowing specially crafted payloads to bypass security rules.

In 64-bit environments the problem occurs less frequently, as the pointer size coincides with the expected size of the memory structure, which "hides" the error in most cases.

Risk of bypassing security rules

This vulnerability could prove particularly dangerous for organizations that still use older infrastructures based on 32-bit operating systems.

Since WAF rules rely on normalized input to detect malicious patterns, any failure in the conversion process can allow attacks to go unnoticed.

The researchers note that the problem is related to the way memory is managed in more than one place in the code, which makes it necessary to install the fixed version instead of temporary interventions.

Until the upgrade is complete, it is recommended to avoid using ModSecurity in i386 environments where possible.

Critical vulnerabilities in ModSecurity - Experts recommend immediate upgrade

The second vulnerability is even more serious

Of greater concern is CVE-2026-52747, which is classified as high risk as it affects the way ModSecurity parses multipart/form-data, which are widely used in data submission and file upload forms.

See also: SourceCodester Class Timetabling: SQL Injection vulnerability CVE-2026-14770

The vulnerability is located in the multipart/form-data parser within libmodsecurity. It occurs when processing non-file-form fields that contain embedded line breaks, such as carriage-return and line-feed sequences. Instead of preserving these line breaks, the parser silently removes them before passing the data to ModSecurity rules.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

As a result, a payload like “A\r\nB” or “A\nB” is converted to “AB” during inspection. However, backend applications typically retain the original formatting, creating a mismatch between what the firewall and what the application processes.

This discrepancy allows attackers to hide malicious input that depends on line breaks, such as certain injection payloads or parser-specific exploits.

Further analysis shows that the problem is caused by a logic error: data previously stored in the buffer is overwritten rather than appended during multi-part analysis.

Even more worrying is the fact that ModSecurity's strict validation mechanisms are not activated, as variables such as MULTIPART_STRICT_ERROR remain unchanged, without generating warnings to administrators.

Why these vulnerabilities matter

ModSecurity is used as a first line of defense against web applications in organizations of all sizes, from small businesses to large service providers and government infrastructures.

When a WAF shows discrepancies between the parsing of requests and the way the application itself processes them, so-called parser inconsistencies, one of the most difficult categories of vulnerabilities in the field of cybersecurity.

In these cases, the firewall considers a request to be safe, while the application interprets the same data differently, allowing the protection mechanisms to be bypassed.

See also: Serious vulnerabilities in Apache ActiveMQ – Update Now

Critical vulnerabilities in ModSecurity - Experts recommend immediate upgrade

Recommendations to administrators

Security experts recommend immediately installing ModSecurity version 3.0.16, which fixes both vulnerabilities.

At the same time, organizations are urged to review rulesets based on input transformations and multipart data checking to confirm that they work correctly in all supported environments.

The case is a reminder that even mature and widely trusted security tools can develop dangerous “blind spots” due to a seemingly small programming error. As cyberattacks become increasingly complex, regular updates to defense mechanisms, continuous evaluation of security rules , and systematic infrastructure audits are essential prerequisites for effective protection of modern web applications.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS