HIGH🇵🇱 Wersja polska

CVE-2025-47947

CVSS 7.5v3.1pub. 2025-05-21upd. 2025-06-20

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action. A patch is available at pull request 3389 and expected to be part of version 2.9.9. No known workarounds are available.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Trustwave Modsecurity

    APP
    Trustwave
    < 2.9.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSFirewall
CWE
References

Related vulnerabilities

CVE-2025-27110HIGH7.9same product

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ...

CVE-2024-46292HIGH7.5same product

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted inp...

CVE-2023-24021HIGH7.5same product

Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Fir...

CVE-2022-48279HIGH7.5same product

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could by...

CVE-2021-42717HIGH7.5same product

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting te...