CVE-2026-52747Patch(owasp / modsecurity)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch owasp modsecurity systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-180

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • modsecurity

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 10 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-07-06); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
modsecurity

Deep dive

Activity timeline10 mentions / 5d
01234Mentions · 2026-07-06: 4Mentions · 2026-07-11: 1Mentions · 2026-07-13: 2Mentions · 2026-07-15: 2Mentions · 2026-07-31: 1Patch / Workaround · 2026-07-06: 3Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-13: 2Patch / Workaround · 2026-07-15: 2Technical Details · 2026-07-06: 4Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 2Technical Details · 2026-07-15: 2Technical Details · 2026-07-31: 107-0607-1107-1307-1507-31
Signal classification3 categories
Patch
660.0%
Disclosure
330.0%
General
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-064
Disclosure1Patch3
2026-07-111
Patch1
2026-07-132
Disclosure1Patch1
2026-07-152
Disclosure1Patch1
2026-07-311
General1
Full discourse10 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two ModSecurity vulnerabilities let attackers slip past WAF rules via a multipart parser bug (CVE-2026-52747). Update to ModSecurity v3.0.16 now. #ModSecurity #WAF #WAFBypass #OWASP #CVE202652747 #CVE202652761 #Vulnerability http://securityonline.info/modsecurity-vulnerabilities-cve-2026-52747/

    Post summary

    The post alerts about ModSecurity multipart parser vulnerabilities (CVE‑2026‑52747) and recommends updating to v3.0.16 to mitigate the risk.

    0301771.5K
    12.9K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    ModSecurityで2件の脆弱性が修正。WAFルール回避に使用可能なもの。multipart/form-dataにおける埋め込まれた改行の取り扱いの不備CVE-2026-52747(CVSSスコア8.6)とt:utf8toUnicode変換の返値誤りCVE-2026-52761(CVSSスコア5.8)。 https://securityonline.info/modsecurity-vulnerabilities-cve-2026-52747/

    Post summary

    ModSecurity’s two vulnerabilities—CVE‑2026‑52747 (CVSS 8.6) and CVE‑2026‑52761 (CVSS 5.8)—have been fixed, with a link to more details.

    010831.0K
    7.7K followersView on X
  • キタきつね@foxbook
    Disclosure

    ModSecurityの脆弱性により、攻撃者がWAFルールを回避できる ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules #DailyCyberSecurity (Jul 6) https://securityonline.info/modsecurity-vulnerabilities-cve-2026-52747/

    Post summary

    The article announces a ModSecurity vulnerability (CVE‑2026‑52747) that enables attackers to bypass WAF rules, without mentioning exploitation tools, active attacks, or available fixes.

    01041488
    5.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-52747 - WAF bypass in ModSecurity <3.0.16. Multipart parser silently removes line breaks, creating parser differential vs backend. CVSS 8.6. No patch available. Upgrade to 3.0.16 immediately. #CVE #ModSecurity #infosec #devsecops #devops #developers #git

    Post summary

    The text announces a CVE-2026-52747 vulnerability in ModSecurity with a high CVSS score, explains the technical issue and recommends an upgrade even though no patch is yet available.

    1000074
    979 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-52747 - #WAF bypass in #ModSecurity <3.0.16. Multipart parser silently removes line breaks, creating parser differential vs backend. #CVSS 8.6. No patch available. Upgrade to 3.0.16 immediately. #CVEAlert #ModSecurity #infosec #devsecops #devops #developers #sysadmin

    Post summary

    The tweet announces CVE‑2026‑52747, a WAF bypass caused by multipart parsing differences, assigns a CVSS score of 8.6, and advises upgrading to ModSecurity 3.0.16 as the only mitigation.

    1000085
    978 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-52747: ModSecurity Multipart Parser Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rvwV40

    Post summary

    The text references CVE-2026-52747, a ModSecurity multipart parser bug, but it does not provide evidence of a PoC, exploit, active exploitation, patch details, or a false positive claim.

    0000045
    31 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    https://www.valtersit.com/cve/CVE-2026-52747

    Post summary

    The page provides a technical description of CVE‑2026‑52747, notes that a vendor patch is available, but does not mention active exploitation or a proof‑of‑concept.

    000003
    979 followersView on X
  • iototsecnews@iototsecnews
    Patch

    ModSecurity WAF の脆弱性 CVE-2026-52761/52747 が FIX:検証回避の恐れ https://iototsecnews.jp/2026/07/06/modsecurity-security-flaws-enable-waf-rule-evasion-with-crafted-http-requests/ 今回の WAF の脆弱性は、プログラムの処理における認識のズレが原因となっています。 CVE-2026-52761 では、ポインタ・サイズの誤計算により、 32-bit 環境におけるデータの不適切な処理が発生し、正常な検知ができなくなります。また CVE-2026-52747 では、マルチパート形式のデータを解析する際に、改行コードを不適切に除去してしまうことで、 WAF とバックエンドのシステムとの間でデータの解釈に差異が生まれてしまいます。これらのプログラム内の計算ミスや文字列の不適切な処理という根本的な原因が、セキュリティ・チェックをすり抜ける隙を作っています。ご利用のチームは、ご注意ください。 #CVE202652747 #CVE202652761 #ModSecurity #Vulnerability #WAF

    Post summary

    The article announces that ModSecurity WAF vulnerabilities CVE‑2026‑52761 and CVE‑2026‑52747 have been fixed, explains the technical causes of detection bypass, and urges users to be cautious.

    00000135
    500 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-52747 (CVSS 8.6): ModSecurity WAF <3.0.16 has a multipart/form-data parser issue. Update to 3.0.16+ if you use this engine on Apache, IIS or Nginx. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/hTzY3XNpHi

    Post summary

    The tweet announces CVE‑2026‑52747 as a multipart/form-data parser issue in ModSecurity WAF versions below 3.0.16, assigns a CVSS 8.6 score, and recommends updating to 3.0.16 or later on Apache, IIS, or Nginx.

    0000065
    89 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Two ModSecurity WAF bypass flaws disclosed — patch to v3.0.16 now! 🕳️ CVE-2026-52747 (High, 7.5): The multipart parser strips line breaks from form fields — WAF sees one value, backend sees another. Payloads slip past rules undetected. 🐛 CVE-2026-52761 (Moderate, 5.3): sizeof() on a pointer bug breaks UTF-8 normalization on i386 — rules relying on it can be bypassed. ⬆️ Upgrade immediately + avoid i386 deployments.

    Post summary

    The tweet announces two ModSecurity WAF bypass vulnerabilities, provides technical details, and urges users to immediately install the v3.0.16 patch and avoid i386 deployments.

    0000061
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appowaspmodsecurity---

Explore more