Incomplete filtering of multiple instances of special elements in OWASP ModSecurity Core Rule Set (CRS) - CVE-2026-21876
Published: January 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass security rules.
The vulnerability exists due to improper input validation of multiplart requests in rule 922110. When the first rule in a chain iterates over a collection (like MULTIPART_PART_HEADERS), the capture variables (TX:0, TX:1) get overwritten with each iteration. Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has a legitimate charset. A remote non-authenticated attacker can bypass ModSecurity rule and send malicious requests to the application.
Affected software
LoadMaster
Debian Linux
openEuler
MOVEit WAF
mod_security_crs
modsecurity-crs (Debian package)
How to mitigate CVE-2026-21876
MOVEit WAF - update to 7.2.63.0
mod_security_crs - addressed in versions 3.2.2-3, 3.3.5-3
modsecurity-crs (Debian package) - addressed in versions 3.3.4-1+deb12u1, 3.3.7-1+deb13u1
LoadMaster - addressed in versions 7.2.54.17, 7.2.63.1
External References
Related Security Bulletins
- Multipart bypass using multiple content-type parts in ModSecurity Core Rule Set
- openEuler 24.03 LTS SP1 update for mod_security_crs
- openEuler 24.03 LTS update for mod_security_crs
- openEuler 22.03 LTS SP4 update for mod_security_crs
- openEuler 22.03 LTS SP3 update for mod_security_crs
- openEuler 24.03 LTS SP3 update for mod_security_crs
- openEuler 24.03 LTS SP2 update for mod_security_crs
- Debian update for modsecurity-crs
- openEuler 20.03 LTS SP4 update for mod_security_crs
- Multiple vulnerabilities in Progress MOVEit WAF
- Multiple vulnerabilities in Progress LoadMaster