Improper Handling of Case Sensitivity in OWASP ModSecurity Core Rule Set (CRS) - #VU153222

 

Improper Handling of Case Sensitivity in OWASP ModSecurity Core Rule Set (CRS) - #VU153222

Published: October 3, 2026


Vulnerability identifier: #VU153222
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-178
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass charset allow-list enforcement and evade downstream detection rules.

The vulnerability exists due to improper handling of case sensitivity in rule 920480 in the REQUEST-920-PROTOCOL-ENFORCEMENT.conf rule set when processing Content-Type request headers with uppercase or mixed-case charset parameter names. A remote attacker can send a request with a non-lowercase CHARSET parameter name to bypass charset allow-list enforcement and evade downstream detection rules.

The issue affects deployments using paranoia level 1 or 2 that rely on rule 920480; encoding-based filter evasion additionally depends on the backend honoring the declared charset when decoding the request body.


Affected software

OWASP ModSecurity Core Rule Set (CRS)

Remediation

Install security update from vendor's website.

OWASP ModSecurity Core Rule Set (CRS) - addressed in versions 4.25.2, 4.30.0

External References

Related Security Bulletins