CVE-2025-48866

Published Jun 2, 2025

Last updated 8 months ago

Overview

Description
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.
Source
security-advisories@github.com
NVD status
Analyzed
Products
modsecurity

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-1050

Social media

Hype score
Not currently trending
  1. URGENT: #Oracle Linux 9 mod_security DoS Patch (CVE-2025-48866) - ELSA-2025-12838 Risk: Moderate (Service disruption). Patch NOW via ULN! Read more:👉 https://t.co/0XtB4rKmJl https://t.co/uCANPLlM6s

    @Cezar_H_Linux

    6 Aug 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Critical update for #openSUSE: Patch apache2-mod_security2 now for CVE-2025-47947 & CVE-2025-48866 DoS fixes. Affects Leap 15.4/15.6, SLE 15 SP4/5, Manager 4.3. Patch cmds: Read more: 👉 https://t.co/kwGpO7w3hE #CyberSecurity #LinuxAdmin https://t.co/ucT8GZL7Fj

    @Cezar_H_Linux

    19 Jun 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ModSecurity flaw CVE-2025-48866 lets remote attackers crash servers via argument sanitization, risking web systems using Apache, IIS, and Nginx. #CyberSecurity #ModSecurity #ServerVulnerability https://t.co/nlmyAyhGdp

    @CyberSecTV_eu

    15 Jun 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. آیا می دانستید که برای WAF ها نیز آسیب پذیری منتشر می شود؟ به تازگی برای Mod_security که یکی از محبوبترین WAF ها می باشد ، آسیب پذیری جدیدی با کد شناسایی (CVE-2025-48866) از

    @AmirHossein_sec

    4 Jun 2025

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-48866 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vu… https://t.co/KcTNLIJ7Zk

    @CVEnew

    2 Jun 2025

    363 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations