Known vulnerabilities in OWASP OWASP ModSecurity Core Rule Set (CRS) 3.0.2
4.25.0
3.3.9
4.24.1
4.24.0
4.23.0
3.3.8
4.22.0
4.21.0
4.20.0
4.19.0
4.18.0
4.17.1
4.17.0
4.16.0
4.15.0
4.14.0
4.13.0
4.12.0
4.11.0
4.10.0
4.9.0
3.3.7
4.8.0
4.7.0
3.3.6
4.6.0
4.5.0
4.4.0
4.3.0
4.2.0
4.1.0
4.0.0
3.3.5
3.3.4
3.2.3
3.3.3
3.2.2
3.3.2
3.3.0
3.2.1
3.2.0
3.1.2
3.1.1
3.1.0
3.0.2
3.0.1
3.0.0
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
Security bulletins (5)
| Secuity bulletin | Severity | Status | Published |
|---|---|---|---|
| SB2026010786: Multipart bypass using multiple content-type parts in ModSecurity Core Rule Set | Medium | 07.01.2026 | |
| SB2023072508: Type Confusion in coreruleset | Medium | 25.07.2023 | |
| SB2021070111: WAF ruleset bypass in OWASP ModSecurity Core Rule Set (CRS) | Medium | 01.07.2021 | |
| SB2019072816: Denial of service in OWASP ModSecurity Core Rule Set (CRS) | Medium | 28.07.2019 | |
| SB2019070929: File upload rules bypass in OWASP ModSecurity Core Rule Set (CRS) | Medium | 09.07.2019 |