CVE-2025-47947(trustwave / modsecurity)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action. A patch is available at pull request 3389 and expected to be part of version 2.9.9. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1050

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • modsecurity

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
modsecurity

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-04: 110-04
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 CVE-2025-47947 — ModSecurity v2 DoS PoC yayınlandı. ModSecurity ≤2.9.8'de, application/json istekleri ve sanitiseMatchedBytes kullanan aktif bir kural üzerinden JSON değişkenlerinin sanitize tablosunda N² büyümesine neden olunabiliyor. Sonuç olarak Apache worker aşırı RAM tüketerek OOM killer tarafından sonlandırılabiliyor. Unauthenticated Remote DoS (RCE veya Authentication Bypass değil) 2.9.9 sürümünde düzeltildi. https://github.com/yel1337/CVE-2025-47947

    020125685
    2.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptrustwavemodsecurity---

Explore more