#VU112103 Buffer overflow in ModSecurity - CVE-2025-52891

 

#VU112103 Buffer overflow in ModSecurity - CVE-2025-52891

Published: July 2, 2025 / Updated: July 2, 2025


Vulnerability identifier: #VU112103
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-52891
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
ModSecurity
Software vendor:
Trustwave

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing XML data with an empty XML tag. A remote attacker can send specially crafted XML data to the web application protected with ModSecurity, trigger memory corruption and perform a denial of service (DoS) attack.

Note, the vulnerability affects installations with SecParseXmlIntoArgs set to "On" or "OnlyArgs", which is not the default configuration. 


Remediation

Install updates from vendor's website.

External links