Beveiligingsadvies

CVE-2026-42268

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-12 21:40:19
Laatst bijgewerkt 2026-05-14 12:34:20
Toegewezen door GitHub_M
CVSS-score 8.2
Status PUBLISHED

Beschrijving

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.