Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-52761

Опубликовано: 10 июл. 2026
Источник: nvd
CVSS3: 5.8
CVSS3: 5.3
EPSS Низкий

Описание

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.15 (включая)

EPSS

Процентиль: 34%
0.00414
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-467

Связанные уязвимости

CVSS3: 5.8
ubuntu
26 дней назад

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.

CVSS3: 5.8
redhat
26 дней назад

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.

CVSS3: 5.8
debian
26 дней назад

ModSecurity is an open source, cross platform web application firewall ...

EPSS

Процентиль: 34%
0.00414
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-467