Out-of-bounds read in ModSecurity - CVE-2026-30923
Published: April 29, 2026
ModSecurity
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the t:hexDecode transformation when processing query strings containing a single character under a rule that inspects query string arguments. A remote attacker can send a specially crafted request to cause a denial of service.
Only configurations that use the t:hexDecode transformation on query string inspection are vulnerable.