Improper Handling of Extra Parameters in OWASP ModSecurity Core Rule Set (CRS) - #VU153223

 

Improper Handling of Extra Parameters in OWASP ModSecurity Core Rule Set (CRS) - #VU153223

Published: October 3, 2026


Vulnerability identifier: #VU153223
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-235
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass multipart charset protections.

The vulnerability exists due to improper handling of extra parameters in rule 922100 when processing multipart requests containing an additional argument or an allowed charset after a blocked charset. A remote attacker can send a crafted multipart request to bypass multipart charset protections.


Affected software

OWASP ModSecurity Core Rule Set (CRS)

Remediation

Install security update from vendor's website.

OWASP ModSecurity Core Rule Set (CRS) - addressed in versions 4.25.2, 4.30.0

External References

Related Security Bulletins