PatchSiren

owasp-modsecurity CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM owasp-modsecurity CVE published 2026-07-10

CVE-2026-52761

CVE-2026-52761 is a vulnerability in ModSecurity, an open-source web application firewall engine. The t:utf8toUnicode transformation in versions 3.0.0 through 3.0.15 produces incorrect output on i386 architecture due to improper use of snprintf. This issue allows rules using this transformation to be bypassed on i386 architecture, potentially leading to security risks. The vulnerability is fixed in versio [truncated]

HIGH owasp-modsecurity CVE published 2026-07-10

CVE-2026-52747

The CVE record for CVE-2026-52747 was published on 2026-07-10T22:16:42.697Z. This high-severity vulnerability affects EasyApache 4's ea-modsec30, allowing an unauthenticated WAF rule bypass. The vulnerability is caused by the multipart/form-data request body parser in ea-modsec30 invalidly handling and characters. Defenders should prioritize verifying exposure, updating to version 3.0.16, and monitoring f [truncated]