Denial of Service Vulnerability in ModSecurity Web Application Firewall Engine
CVE-2025-48866
7.5HIGH
What is CVE-2025-48866?
ModSecurity, a widely-used open-source web application firewall, is susceptible to a denial of service vulnerability due to the sanitiseArg
action. This vulnerability enables an attacker to manipulate the number of arguments processed, leading to service interruptions. To mitigate the risk, users are advised to upgrade to version 2.9.10 or later and refrain from utilizing rules involving the sanitiseArg
action until the upgrade is applied.
Affected Version(s)
ModSecurity < 2.9.10