← Back to CVE List
CVE-2026-73857NVD
Vulnerability Summary
Tobias Klein (<tk@trapkit.de>) reported this issue in e-mail. Impact A remote, unauthenticated attacker can, with a single crafted HTTP request, make a web server worker process running ModSecurity dereference an uninitialized pointer (`XMLNodes::parsing_ctx_arg`) in the XML-into-ARGS SAX end-element callback, resulting in a write of a constant value to an attacker-controlled address (a restricted write-what-where primitive). Impact ranges from denial of service to memory disclosure and execution-flow redirection (possibly leading to remote code execution). The defect is reachable only when the `SecParseXmlIntoArgs` directive is set to `On` or `OnlyArgs` (it is `Off` by default). Affected: v3.0.15, v3.0.16 and current v3/master. The code path was introduced in v3.0.15. Earlier v3.0.x releases and ModSecurity v2.x are not affected. Patches Not yet, next release will contain that. Workarounds Be sure the `SecParseXmlIntoArgs` is `Off`.
CVSS v3.1 Base Metrics — Score 7.5
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- libmodsecurity3 < 3.0.17
- libmodsecurity3 3.0.17