Known vulnerabilities in OWASP OWASP ModSecurity Core Rule Set (CRS)
4.25.0
3.3.9
4.24.1
4.24.0
4.23.0
3.3.8
4.22.0
4.21.0
4.20.0
4.19.0
4.18.0
4.17.1
4.17.0
4.16.0
4.15.0
4.14.0
4.13.0
4.12.0
4.11.0
4.10.0
4.9.0
3.3.7
4.8.0
4.7.0
3.3.6
4.6.0
4.5.0
4.4.0
4.3.0
4.2.0
4.1.0
4.0.0
3.3.5
3.3.4
3.2.3
3.3.3
3.2.2
3.3.2
3.3.0
3.2.1
3.2.0
3.1.2
3.1.1
3.1.0
3.0.2
3.0.1
3.0.0
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
Security bulletins (6)
| Secuity bulletin | Severity | Status | Published |
|---|---|---|---|
| SB2026010786: Multipart bypass using multiple content-type parts in ModSecurity Core Rule Set | Medium | 07.01.2026 | |
| SB2023072508: Type Confusion in coreruleset | Medium | 25.07.2023 | |
| SB2023020956: Multiple vulnerabilities in OWASP ModSecurity Core Rule Set (CRS) | Medium | 09.02.2023 | |
| SB2021070111: WAF ruleset bypass in OWASP ModSecurity Core Rule Set (CRS) | Medium | 01.07.2021 | |
| SB2019072816: Denial of service in OWASP ModSecurity Core Rule Set (CRS) | Medium | 28.07.2019 | |
| SB2019070929: File upload rules bypass in OWASP ModSecurity Core Rule Set (CRS) | Medium | 09.07.2019 |