Buffer overflow in ModSecurity - CVE-2025-52891
Published: July 2, 2025 / Updated: July 2, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing XML data with an empty XML tag. A remote attacker can send specially crafted XML data to the web application protected with ModSecurity, trigger memory corruption and perform a denial of service (DoS) attack.
Note, the vulnerability affects installations with SecParseXmlIntoArgs set to "On" or "OnlyArgs", which is not the default configuration.
Affected software
EasyApache
openEuler
mod_security-debugsource
mod_security-debuginfo
mod_security
How to mitigate CVE-2025-52891
EasyApache - update to 4 25-22
mod_security-debugsource - update to 2.9.11-1
mod_security-debuginfo - update to 2.9.11-1
mod_security - update to 2.9.11-1
External References
Related Security Bulletins
- Remote denial of service in ModSecurity XML parser
- cPanel EasyApache4 update for PHP
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 20.03 LTS SP4 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security