Unhandled Exception Vulnerability in ModSecurity WAF by OWASP
CVE-2026-42268

8.2HIGH

Key Information:

Vendor
CVE Published:
12 May 2026

What is CVE-2026-42268?

ModSecurity, an open-source web application firewall, is susceptible to an unhandled exception due to an unsigned integer underflow in libmodsecurity3. This vulnerability occurs when an administrator employs specific rules, such as @verifySSN, @verifyCPF, or @verifySVNR, within versions 3.0.0 to below 3.0.15. The issue can lead to unexpected behavior and potential security implications if not addressed. The vulnerability has been resolved in version 3.0.15.

Affected Version(s)

ModSecurity >= 3.0.0, < 3.0.15

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.