
🚨 One-Line Script Can Crash ModSecurity v3 WAFs https://securityonline.info/libmodsecurity3-dos-vulnerabilities-cve-2026-30923-patch-guide/ Two libmodsecurity3 flaws can put ModSecurity v3 WAF availability at risk. CVE-2026-30923 can crash worker processes with a tiny malformed query string when t:hexDecode is used. The advisory says a simple one-line bash loop can keep crashing workers until legit users have nothing left to connect to. A second bug, CVE-2026-42268, affects rules using verifySSN, verifyCPF, or verifySVNR. libmodsecurity3 3.0.15 includes fixes for both vulnerabilities. #ThreatIntelligence #ModSecurity #CyberSecurity #InfoSec
Post summary
The tweet highlights two ModSecurity v3 WAF CVEs that can be exploited with a simple one‑line bash script causing denial‑of‑service, while noting the bugs are patched in version 3.0.15.

