CVEFinder.io

CVE-2024-1019

⚠️ high
🔍 Scan for this CVE
Summary

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end

Description

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.

CVSS Score
8.6
High
EPSS Score
0.3
Exploit Probability
Published Date
2024-01-30
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 80.5% of all 326,604 vulnerabilities in our database.

#63,570
Top 25% most severe
Severity Percentile
Last Modified 2025-07-03
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-42268 ⚠️ high 7.5 0.0 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.... 2026-05-12
CVE-2026-30923 ⚠️ high 7.5 0.0 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec... 2026-05-05
CVE-2025-54571 🔶 medium 6.1 0.1 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio... 2025-08-06
CVE-2025-48866 ⚠️ high 7.5 0.3 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ... 2025-06-02
CVE-2023-38285 ⚠️ high 7.5 0.5 Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity. 2023-07-26
CVE-2023-28882 ⚠️ high 7.5 0.1 Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) be... 2023-04-28
These CVEs affect the same products