OWASP disclosed CVE-2026-33691, a vulnerability in the Core Rule Set (CRS) that lets attackers evade file upload extension checks by appending whitespace to filenames. The bypass can allow dangerous server-executable files such as .php, .phar, .jsp, and .jspx to be uploaded, creating a path to web shell deployment if the backend later normalizes or trims the filename before execution.
The issue is considered most impactful on Windows backends, where trailing whitespace in filenames may be normalized automatically, while Linux systems are generally harder to exploit unless the application or web server explicitly trims names with functions such as strip() or trim(). OWASP patched the flaw in CRS 3.3.9, 4.25.x LTS, and 4.8.x, with fixes backported to supported branches; the vulnerability was reported by RelunSec (also known as @HackingRepo on GitHub).

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
A Rapid7 Metasploit pull request introduced an option to bypass OWASP CRS protections for CVE-2026-33691 using whitespace-padded filenames. The development was tracked in Metasploit's workflow and attributed to smcintyre-r7.
A public advisory disclosed technical details of the OWASP CRS whitespace padding bypass, including that Linux exploitation is less straightforward unless backend applications or web servers trim filenames before execution.
OWASP CRS fixed the vulnerability in versions 3.3.9, 4.25.x LTS, and 4.8.x, and backported the security fix to supported branches.
The whitespace padding file upload bypass in OWASP CRS was assigned CVE-2026-33691. The flaw can allow dangerous files such as .php, .phar, .jsp, and .jspx to pass extension checks, with higher risk on Windows backends that normalize or trim whitespace.
RelunSec, also known as @HackingRepo on GitHub, reported a vulnerability in OWASP Core Rule Set that allows file upload extension checks to be bypassed by padding filenames with whitespace.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceseclists.org
Open sourcenews.ycombinator.com
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.