Bug 2367903 (CVE-2025-47947) - CVE-2025-47947 modsecurity: ModSecurity Has Possible DoS Vulnerability
Summary: CVE-2025-47947 modsecurity: ModSecurity Has Possible DoS Vulnerability
Keywords:
Status: NEW
Alias: CVE-2025-47947
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2367907 2367908
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-21 23:01 UTC by OSIDB Bzimport
Modified: 2025-06-05 16:05 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:8605 0 None None None 2025-06-05 16:05:30 UTC

Description OSIDB Bzimport 2025-05-21 23:01:34 UTC
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action. A patch is available at pull request 3389 and expected to be part of version 2.9.9. No known workarounds are available.

Comment 2 errata-xmlrpc 2025-06-05 16:05:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:8605 https://access.redhat.com/errata/RHSA-2025:8605


Note You need to log in before you can comment on or make changes to this bug.