- Description
- The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- owasp_modsecurity_core_rule_set
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-178
- Hype score
- Not currently trending
⚠️ Vulnerabilidad en productos Progress ❗ CVE-2026-8037 ❗ CVE-2026-33691 ➡️ Más info: https://t.co/pHWOxl9bky https://t.co/4dzHP34ERB
@CERTpy
13 Jul 2026
201 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerabilidad en productos Progress ❗ CVE-2026-8037 ❗ CVE-2026-33691 ➡️ Más info: https://t.co/SPwHWmm3cm https://t.co/JlAMWbyS2X
@CERTpy
19 Jun 2026
77 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【Progress Kemp LoadMasterに未認証RCE脆弱性】 Progress Kemp LoadMasterに、CVE-2026-8037とCVE-2026-33691の2件の脆弱性が公表されました。CVE-2026-8037はAPIの入力検証不備に起因するOSコマンドインジェクションで、認証なしに任
@01ra66it
7 Jun 2026
327 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Progress issued a LoadMaster security bulletin on two flaws CVE-2026-8037 and CVE-2026-33691 disclosed in June 2026, according to Canada's Cyber Centre. https://t.co/NOPtr7ylqT
@threatcluster
6 Jun 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*",
"matchCriteriaId": "33F8A888-1ED5-40BC-B1B9-7AA88411B0E0",
"versionEndExcluding": "3.3.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8822CE75-E018-4576-B30B-A25A1A2F60E0",
"versionEndExcluding": "4.25.0",
"versionStartIncluding": "4.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]