Threat Advisory

ModSecurity Vulnerabilities Compromise Web Services and Weaken TLS Defenses

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting ModSecurity have been identified, specifically impacting libmodsecurity3 and the legacy mod_security2 branch. These bugs cause uninitialized pointer dereferences, response body inspection bypasses, and WAF evasion, exposing underlying web servers to operational risks. Consequently, attackers could leak sensitive database passwords, crash worker processes, or potentially execute arbitrary code on the server.

CVE-2026-73856 (CVSS 8.6 — High): ModSecurity used a case-sensitive Content-Type comparison that could cause response body inspection to be skipped when MIME types such as Text/Html did not match the configured text/html value, bypassing RESPONSE_BODY rules.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting ModSecurity have been identified, specifically impacting libmodsecurity3 and the legacy mod_security2 branch. These bugs cause uninitialized pointer dereferences, response body inspection bypasses, and WAF evasion, exposing underlying web servers to operational risks. Consequently, attackers could leak sensitive database passwords, crash worker processes, or potentially execute arbitrary code on the server.

CVE-2026-73856 (CVSS 8.6 — High): ModSecurity used a case-sensitive Content-Type comparison that could cause response body inspection to be skipped when MIME types such as Text/Html did not match the configured text/html value, bypassing RESPONSE_BODY rules.[emaillocker id="1283"]

CVE-2026-73857 (CVSS 7.5 — High): ModSecurity allows a remote unauthenticated attacker to trigger an uninitialized pointer dereference in the XML-into-ARGS SAX end-element callback through a crafted HTTP request resulting in a restricted write-what-where primitive.

CVE-2026-61813 (CVSS 3.7 — Low): ModSecurity configures libcurl with a non-strict TLS hostname verification value when retrieving content over HTTPS. Depending on the underlying libcurl version, this can weaken verification of the remote server's identity and increase the risk of interception during remote rule downloads.

CVE-2026-61812 (CVSS 5.3 — Medium): ModSecurity's HTML entity decoder recognized only five named entities due to an outdated hand-maintained list that could cause WAF rule evasion through unrecognized HTML entities instead of using the WHATWG named character reference list.

RECOMMENDATION:

We recommend you to update ModSecurity to version 3.0.17 or 2.9.15 or later.

 

The following reports contain further technical details:

[/emaillocker]
crossmenu