PT-2026-28792 · Unknown · Kusanagi-Mod Security Crs

·

CVE-2026-33691

·

Published

2026-01-01

·

Updated

2026-08-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OWASP Core Rule Set versions prior to 3.3.9 OWASP Core Rule Set versions prior to 4.25.0
Description A bypass exists in the OWASP Core Rule Set (CRS), a set of generic attack detection rules for web application firewalls. The issue allows the upload of files with dangerous extensions such as .php, .phar, .jsp, and .jspx by inserting whitespace padding into the filename. This occurs because the affected rules fail to normalize whitespace before evaluating the file extension regular expression, causing the dot-extension check to fail. This bypass is most practical on Windows systems and could potentially lead to Remote Code Execution (RCE) if the underlying application is vulnerable.
Recommendations Update to version 3.3.9. Update to version 4.25.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33691
GHSA-RW5F-9W43-GV2W
OPENSUSE-SU-2026:11632-1

Affected Products

Kusanagi-Mod Security Crs