Improper Handling of Case Sensitivity in OWASP ModSecurity Core Rule Set (CRS) - #VU153222
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass charset allow-list enforcement and evade downstream detection rules.
The vulnerability exists due to improper handling of case sensitivity in rule 920480 in the REQUEST-920-PROTOCOL-ENFORCEMENT.conf rule set when processing Content-Type request headers with uppercase or mixed-case charset parameter names. A remote attacker can send a request with a non-lowercase CHARSET parameter name to bypass charset allow-list enforcement and evade downstream detection rules.
The issue affects deployments using paranoia level 1 or 2 that rely on rule 920480; encoding-based filter evasion additionally depends on the backend honoring the declared charset when decoding the request body.