CVE-2026-42268

HIGH

ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators

Title source: cna
STIX 2.1

Description

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0040
EPSS Percentile 31.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-191 CWE-248
Status published
Products (2)
owasp/modsecurity 3.0.0 - 3.0.15
owasp-modsecurity/ModSecurity >= 3.0.0, < 3.0.15
Published May 12, 2026
Tracked Since May 13, 2026