BIT-modsecurity-2026-42268

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/modsecurity/BIT-modsecurity-2026-42268.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-modsecurity-2026-42268
Aliases
Published
2026-05-14T08:48:16.255Z
Modified
2026-05-14T09:26:25.519776310Z
Summary
ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
Details

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::outofrange) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:trustwave:modsecurity:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / modsecurity

Package

Name
modsecurity
Purl
pkg:bitnami/modsecurity

Severity

  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.0.15

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/modsecurity/BIT-modsecurity-2026-42268.json"