Bug 2476872 (CVE-2026-42268) - CVE-2026-42268 mod_security: ModSecurity: Denial of Service via unsigned integer underflow in rule verification functions
Summary: CVE-2026-42268 mod_security: ModSecurity: Denial of Service via unsigned inte...
Keywords:
Status: NEW
Alias: CVE-2026-42268
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2481129 2481130
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-12 22:02 UTC by OSIDB Bzimport
Modified: 2026-05-25 07:36 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-12 22:02:48 UTC
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.


Note You need to log in before you can comment on or make changes to this bug.