Improper Handling of Extra Parameters in OWASP ModSecurity Core Rule Set (CRS) - #VU153223
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass multipart charset protections.
The vulnerability exists due to improper handling of extra parameters in rule 922100 when processing multipart requests containing an additional argument or an allowed charset after a blocked charset. A remote attacker can send a crafted multipart request to bypass multipart charset protections.