PT-2026-55934 · Unknown · Modsecurity
CVE-2026-52761
·
Published
2026-07-06
·
Updated
2026-07-15
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ModSecurity versions 3.0.0 through 3.0.15
Description
The
t:utf8toUnicode transformation in src/actions/transformations/utf8 to unicode.cc produces incorrect output on i386 architecture. This occurs because the snprintf() function uses sizeof on a char pointer instead of the actual length of the unicode buffer, which allows security rules utilizing this transformation to be bypassed on i386 systems.Recommendations
Update to version 3.0.16.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modsecurity