CVE-2026-42268
EUVD-2026-2985412.05.2026, 22:16
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| owasp | modsecurity | 3.0.0 ≤ 𝑥 < 3.0.15 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration