Multiple newly disclosed vulnerabilities in OWASP ModSecurity could let attackers bypass web application firewall protections by exploiting parsing differences, malformed input, transformation errors, and resource limits.
The flaws affect functions commonly used to inspect HTTP requests and responses, raising concerns for organizations that rely on ModSecurity rules to detect malicious payloads.
One of the most serious issues, tracked as GHSA-5pww-8rfg-9crf, involves the RFC 2231 filename* parameter in multipart HTTP uploads.
ModSecurity applies strict validation rules to filenames, but RFC-compliant application backends written in Go, Python, Node.js, or Java may interpret encoded filename* values differently. An attacker could craft an uploaded file request that the backend accepts while avoiding ModSecurity filename inspection rules.
This mismatch can create a dangerous gap between the firewall and the protected application. Security rules may block suspicious extensions, path traversal strings, or malicious filenames in standard fields.
Meanwhile, the backend processes the RFC 2231-encoded value. The issue is rated High severity because it may allow a malicious file upload or evade security controls designed around multipart filename validation.
Another Moderate-severity vulnerability, GHSA-4j47-8qcr-jf59, affects the t:base64DecodeExt transformation. When the transformation encounters a malformed Base64 padding group, it silently discards the complete decoded output.
As a result, ModSecurity rules relying on the transformed value may see an empty or incomplete string and fail to match an otherwise malicious payload.
Attackers often encode SQL injection, cross-site scripting, command injection, or web shell content to evade signature-based filtering.
If a firewall decodes the data incorrectly and stops inspecting it, it can bypass a rule designed to identify dangerous strings. This flaw illustrates why malformed data handling is as important as normal input processing in web application firewalls.
A third flaw, GHSA-qrch-pjfr-9g47, affects the removeComments transformation. The feature is intended to remove comments from an input before it is checked against security rules.
However, adjacent comments may not be removed correctly, allowing an attacker to split suspicious keywords with comment syntax and potentially evade pattern matching.
For example, a payload can insert comments between fragments of a dangerous command or SQL statement. If ModSecurity fails to normalize the full input, the request may not match a blocking rule even though the backend reconstructs or accepts the malicious expression.
Additional advisories include a High-severity response body inspection bypass, an XML request-body processor pointer dereference flaw, multipart form-data parsing weaknesses, and an issue where PCRE2 @rxGlobal match-limit errors are treated as no match.
Together, the vulnerabilities show that inspection engines can fail when their parsing behavior differs from the applications they protect.
Administrators should review the affected ModSecurity release notes and security advisories, update to patched versions as they become available, and test rules against encoded, malformed, multipart, and comment-obfuscated payloads. Organizations should also use layered defenses rather than depending solely on WAF signatures for application security.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…
A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…
A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…
Every function in a security operations center, from alert triage to incident response, depends on…
ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…
Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…