OWASP ModSecurity maintenance releases fix multiple inspection flaws that could let crafted requests or responses evade web application firewall controls because ModSecurity and protected back-end applications interpret input differently. The issues affect multipart filename* handling under RFC 2231, URL-safe and malformed Base64 decoding, comment obfuscation normalization, multipart parsing, response-body Content-Type processing, XML parsing, and PCRE2 regex match-limit handling. High-severity GHSA-5pww-8rfg-9crf specifically involves inconsistent handling of multipart upload filenames, potentially allowing malicious uploads to bypass WAF rules.
Fixed upstream versions include libmodsecurity 3.0.17 and mod_security2 2.9.15, with exposure dependent on the deployed branch, enabled features, configuration, and distribution packaging. Debian modsecurity-apache packages on Debian 12, 13, and 14 were also flagged for unpatched CVE-2026-61812, rated CVSS 9.8 for remote, unauthenticated impact, although no public exploit or confirmed active exploitation was reported. Organizations should promptly apply applicable vendor updates, confirm the loaded engine and ruleset versions, test rules against malformed and obfuscated inputs, review fail-open behavior, and retain layered application defenses rather than relying solely on WAF signatures.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A Nessus Unix-agent plugin identified CVE-2026-61812 as unpatched on affected Debian Linux 12.0, 13.0, and 14.0 systems, including the Debian modsecurity-apache package. The plugin rates the issue as remotely exploitable with high confidentiality, integrity, and availability impact, while stating that no known exploits are available.
ModSecurity released maintenance updates addressing multipart filename handling, URL-safe Base64 decoding, comment obfuscation, PCRE2 match-limit errors, XML parsing, and response-body Content-Type processing. The associated upstream releases are libmodsecurity 3.0.17 and mod_security2 2.9.15; no active exploitation was confirmed by cited primary sources.
Multiple vulnerabilities were disclosed in OWASP ModSecurity that can let malicious inputs evade WAF inspection through parsing discrepancies, malformed-data handling, transformation failures, and resource-limit conditions. The issues include high-severity GHSA-5pww-8rfg-9crf, involving RFC 2231 multipart filename* handling, as well as Base64 decoding and comment-normalization flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecybersecuritynews.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.