ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modsecurity
Modsecurity modsecurity |
|
| Vendors & Products |
Modsecurity
Modsecurity modsecurity |
Tue, 12 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15. | |
| Title | ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators | |
| Weaknesses | CWE-191 CWE-248 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T21:40:19.031Z
Reserved: 2026-04-26T11:53:27.706Z
Link: CVE-2026-42268
No data.
Status : Undergoing Analysis
Published: 2026-05-12T22:16:34.337
Modified: 2026-05-13T18:14:48.583
Link: CVE-2026-42268
No data.
OpenCVE Enrichment
Updated: 2026-05-13T09:45:09Z