CVE-2026-52761Patch(owasp / modsecurity)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch owasp modsecurity systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-467

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • modsecurity

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
modsecurity

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-06: 1Mentions · 2026-07-13: 1Mentions · 2026-07-15: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-15: 107-0607-1307-15
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-061
Patch1
2026-07-131
General1
2026-07-151
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 ModSecurity WAF, Rule Bypass via Buffer Size Miscalculation, #CVE-2026-52761 (Medium) -DC-Jul2026-965 https://dailycve.com/modsecurity-waf-rule-bypass-via-buffer-size-miscalculation-cve-2026-52761-medium-dc-jul2026-965/

    Post summary

    The post announces CVE‑2026‑52761, describing a ModSecurity WAF rule bypass caused by a buffer size miscalculation, classified as medium severity, with no PoC, patch, or exploitation details provided.

    0000067
    219 followersView on X
  • iototsecnews@iototsecnews
    General

    ModSecurity WAF の脆弱性 CVE-2026-52761/52747 が FIX:検証回避の恐れ https://iototsecnews.jp/2026/07/06/modsecurity-security-flaws-enable-waf-rule-evasion-with-crafted-http-requests/ 今回の WAF の脆弱性は、プログラムの処理における認識のズレが原因となっています。 CVE-2026-52761 では、ポインタ・サイズの誤計算により、 32-bit 環境におけるデータの不適切な処理が発生し、正常な検知ができなくなります。また CVE-2026-52747 では、マルチパート形式のデータを解析する際に、改行コードを不適切に除去してしまうことで、 WAF とバックエンドのシステムとの間でデータの解釈に差異が生まれてしまいます。これらのプログラム内の計算ミスや文字列の不適切な処理という根本的な原因が、セキュリティ・チェックをすり抜ける隙を作っています。ご利用のチームは、ご注意ください。 #CVE202652747 #CVE202652761 #ModSecurity #Vulnerability #WAF

    Post summary

    The article highlights two ModSecurity rule‑evasion vulnerabilities caused by pointer miscalculations and improper newline handling, but does not provide PoC, exploit tools, patch details, or evidence of active exploitation.

    00000135
    500 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Two ModSecurity WAF bypass flaws disclosed — patch to v3.0.16 now! 🕳️ CVE-2026-52747 (High, 7.5): The multipart parser strips line breaks from form fields — WAF sees one value, backend sees another. Payloads slip past rules undetected. 🐛 CVE-2026-52761 (Moderate, 5.3): sizeof() on a pointer bug breaks UTF-8 normalization on i386 — rules relying on it can be bypassed. ⬆️ Upgrade immediately + avoid i386 deployments.

    Post summary

    Two ModSecurity WAF bypass vulnerabilities (CVE-2026-52747 and CVE-2026-52761) have been disclosed, with a patch to v3.0.16 released and immediate upgrade recommended to mitigate the risks.

    0000061
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appowaspmodsecurity---

Explore more