PT-2026-28792 · Unknown · Kusanagi-Mod Security Crs
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OWASP Core Rule Set versions prior to 3.3.9
OWASP Core Rule Set versions prior to 4.25.0
Description
A bypass exists in the OWASP Core Rule Set (CRS), a set of generic attack detection rules for web application firewalls. The issue allows the upload of files with dangerous extensions such as
.php, .phar, .jsp, and .jspx by inserting whitespace padding into the filename. This occurs because the affected rules fail to normalize whitespace before evaluating the file extension regular expression, causing the dot-extension check to fail. This bypass is most practical on Windows systems and could potentially lead to Remote Code Execution (RCE) if the underlying application is vulnerable.Recommendations
Update to version 3.3.9.
Update to version 4.25.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kusanagi-Mod Security Crs