MODSECURITY has four security flaws that were addressed in recent patches. The vulnerabilities affect the ModSecurity WAF engine and could enable bypassing inspection and other weaknesses in parsing and configuration. The maintainers urge admins to upgrade to ModSecurity 3.0.17 or 2.9.15 to mitigate the risks.
The flaws are tracked under four CVEs: CVE-2026-73857, CVE-2026-73856, CVE-2026-61813, and CVE-2026-61812. The highest reported severity is 8.6 (CVSSv3) for one of the flaws, with the others rated accordingly. All four are currently listed as not exploited in the wild, though proof-of-concept material exists for the WAF evasion and inspection-bypass issues. Affected versions include libmodsecurity3 up to 3.0.16 and, for the legacy mod_security2 branch, version 2.9.14 and earlier. There is no confirmed exploitation at present.
How the issues work: one flaw involves an uninitialised pointer dereference during XML body processing; another allows bypassing response-body inspections by sending mixed-case Content-Type headers (e.g., Text/Html rather than the standard lowercase form); a third enables evading detection rules by encoding payloads with HTML entities that the decoder ignores; a fourth stems from a misconfigured libcurl setting that weakens TLS hostname verification during remote rule downloads.
Practical response: upgrade to 3.0.17 (or 2.9.15 for the v2 line) as soon as possible. If patching cannot be completed immediately, disable the SecParseXmlIntoArgs directive and avoid relying solely on t:htmlEntityDecode for critical input normalisation. Administrators should consult the official ModSecurity advisories for full technical details and consider implementing native tokenising detection rules.