CVE-2026-52747
owasp-modsecurity ModSecurity, modsecurity
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_PO...
- CVSS
- 8.6
- EPSS
- 0.52% 41.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11