Bug 2369827 (CVE-2025-48866) - CVE-2025-48866 mod_security: ModSecurity Denial of Service Vulnerability
Summary: CVE-2025-48866 mod_security: ModSecurity Denial of Service Vulnerability
Keywords:
Status: NEW
Alias: CVE-2025-48866
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2369879 2369880
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-02 16:01 UTC by OSIDB Bzimport
Modified: 2025-06-03 17:17 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-06-02 16:01:19 UTC
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the  `sanitiseArg` (or `sanitizeArg`) action.


Note You need to log in before you can comment on or make changes to this bug.