CVE-2026-52747
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 0.48%
- CWE
- CWE-180
- Published
- 2026-07-10
- Last modified
- 2026-07-13
Affected products
- owasp-modsecurity ModSecurity
Weakness type
Related vulnerabilities
- CVE-2026-82736 — Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
- CVE-2026-82481 — The cohttp package before 6.3.0 for OCaml allows directory traversal.
- CVE-2026-76203 — CSS sanitizer bypass in Pentestify report themes allows forced outbound requests
- CVE-2026-73416 — jupyterlab: PyPI extension blocklist package-name canonicalization bypass
- CVE-2026-73420 — NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
- CVE-2026-72917 — AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization
- CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks
- CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope