TL;DR
Project maintainers released patches to address four ModSecurity security vulnerabilities. Specifically, these bugs cause uninitialized pointer dereferences, response body inspection bypasses, and WAF evasion. Administrators must upgrade to version 3.0.17 or 2.9.15 immediately to protect their servers.
- Vulnerabilities: 4 flaws (CVE-2026-73857, CVE-2026-73856, CVE-2026-61813, CVE-2026-61812)
- Highest severity: 8.6 (High · CVSSv3)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Status |
|---|---|---|
| CVE-2026-73856 | 8.6 | Not exploited |
| CVE-2026-73857 | 7.5 | Not exploited |
| CVE-2026-61813 | 3.7 | Not exploited |
| CVE-2026-61812 | Awaiting analysis | Not exploited |
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
ModSecurity acts as the dominant open-source WAF engine, securing millions of domains globally. Unpatched ModSecurity security vulnerabilities expose underlying web servers to severe operational risks. Because administrators rely heavily on this engine for traffic filtering, bypassing its rules puts back-end applications in direct danger. Consequently, attackers could leak sensitive database passwords, crash worker processes, or potentially execute arbitrary code on the server. Therefore, resolving these weaknesses is critical for maintaining infrastructure integrity.
How The Attack Works
These flaws operate through distinct parsing and configuration errors within the engine. First, sending a crafted HTTP request triggers an uninitialized pointer dereference during XML body processing. Second, attackers can bypass response body inspections by sending mixed-case Content-Type headers, such as Text/Html instead of standard lowercase strings. Furthermore, adversaries can evade detection rules by encoding payloads with unsupported HTML entities that the decoder ignores. Finally, a misconfigured libcurl setting weakens TLS hostname verification during remote rule downloads, increasing interception risks.
Exploitation Status
Security researchers published practical proof-of-concept exploits for the WAF evasion and inspection bypass bugs. Fortunately, no active exploitation in the wild has been confirmed for these specific issues.
Affected Versions
These vulnerabilities impact libmodsecurity3 versions 3.0.16 and earlier. Additionally, the HTML decoding flaw directly affects the legacy mod_security2 branch, specifically version 2.9.14 and earlier.
Patch And Mitigation Steps
You must upgrade your installations to version 3.0.17 for v3, or 2.9.15 for v2, to resolve these ModSecurity security vulnerabilities. If you cannot patch immediately, you should disable the SecParseXmlIntoArgs directive entirely. Moreover, do not rely solely on t:htmlEntityDecode for critical input normalization. Instead, use detection rules that tokenize tags natively. Finally, review the official ModSecurity security advisories for complete technical details.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!