Owasp
Owasp Modsecurity Core Rule SET: vulnerabilidades y CVE
Owasp Modsecurity Core Rule SET tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses2
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33691 | Alta (7.5) | 1.6% | — | 2 abr 2026 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading… |
| CVE-2026-21876 | Media (5.3) | 18% | — | 8 ene 2026 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart… |
| CVE-2022-39958 | Alta (7.5) | 1.2% | — | 20 sept 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte… |
| CVE-2022-39957 | Alta (7.5) | 0.99% | — | 20 sept 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded… |
| CVE-2022-39956 | Crítica (9.8) | 1.2% | — | 20 sept 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated… |
| CVE-2022-39955 | Crítica (9.8) | 1.4% | — | 20 sept 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable… |
| CVE-2020-22669 | Crítica (9.8) | 1.3% | — | 2 sept 2022 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF… |
| CVE-2021-35368 | Crítica (9.8) | 2.7% | — | 5 nov 2021 | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname. |
| CVE-2018-16384 | Alta (7.5) | 1.7% | — | 3 sept 2018 | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.