Skip to content

Top Stories

Top Stories

Primary Menu
  • Breaking News
  • UNIT CONVERTER
  • QR Code Generator
  • SEO META TAG GENERATOR
  • Background Remover Tool
  • Image Enhancer Tool
  • Image Converter Tool
  • Image Compressor Tool
  • Keyword Research Tool
  • Paint Tool
  • About Us
  • Contact Us
  • Privacy Policy
HOME PAGE
  • Home
  • Uncategorized
  • ModSecurity WAF Vulnerability Enables DoS Using Empty XML Elements
  • Uncategorized

ModSecurity WAF Vulnerability Enables DoS Using Empty XML Elements

VedVision HeadLines July 3, 2025
ModSecurity WAF Vulnerability Enables DoS Using Empty XML Elements


A newly disclosed vulnerability in ModSecurity, a widely used open-source web application firewall (WAF), exposes servers to denial-of-service (DoS) attacks by exploiting a flaw in the way the software parses empty XML elements.

The flaw, registered as CVE-2025-52891, affects ModSecurity versions 2.9.8 to before 2.9.11 and is rated with a CVSS v3 base score of 6.5 (moderate severity).

Vulnerability Details

The issue arises when the SecParseXmlIntoArgs feature is enabled (set to “On” or “OnlyArgs”).

If an incoming HTTP request has a Content-Type of application/xml and contains at least one empty XML tag (e.g., ), ModSecurity attempts to parse the XML node.

CVE ID Affected Versions Patched Version Severity CVSS
CVE-2025-52891 2.9.8–2.9.10 2.9.11 Moderate 6.5

The vulnerability is triggered because the software uses the strlen() function to determine the length of the XML node’s value; when the node is empty, strlen() is called on a null value, causing a segmentation fault and crashing the WAF process.

This crash can be exploited by an attacker to repeatedly send specially crafted XML payloads, effectively taking down the WAF and potentially exposing the protected web application to further attacks.

The vulnerability only affects mod_security2 and does not impact the newer libmodsecurity3 library, which is written in C++ and does not rely on the same parsing logic.

Impact and Mitigation

  • Attack Vector: Network (remote)
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required (malicious request)
  • Scope: Unchanged
  • Confidentiality/Integrity: None
  • Availability: High (DoS)

By default, the SecParseXmlIntoArgs directive is set to “Off,” so only installations that have enabled this feature are vulnerable.

Administrators are advised to immediately disable SecParseXmlIntoArgs or upgrade to the patched version 2.9.11 as soon as it becomes available.

The vulnerability was reported by Andrew Howe (@RedXanadu), with special thanks to contributors who assisted in identifying and patching the bug.

Administrators using ModSecurity are urged to review their configurations and apply mitigations or updates promptly to safeguard their web infrastructure.

Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free



Source link

Continue Reading

Previous: Bitcoin Mining Has Huge Role In Energy Production Expansion
Next: Your Roku has secret menus and screens – here's how to unlock them – ZDNET

Related News

Donald Trump Jr. Invests  Million In Bitcoin Treasury Company Thumzup Media
  • Uncategorized

Donald Trump Jr. Invests $4 Million In Bitcoin Treasury Company Thumzup Media

VedVision HeadLines July 10, 2025
NextEra, First Solar, Nextracker Resist OBBB Solar Cuts
  • Uncategorized

NextEra, First Solar, Nextracker Resist OBBB Solar Cuts

VedVision HeadLines July 10, 2025
Bitcoin Bull Eyes 0K After BTC Reaches New All-Time High
  • Uncategorized

Bitcoin Bull Eyes $150K After BTC Reaches New All-Time High

VedVision HeadLines July 10, 2025

Recent Posts

  • Three-language policy was withdrawn to avoid law and order problems: Ravindra Chavan | Mumbai News
  • Donald Trump Jr. Invests $4 Million In Bitcoin Treasury Company Thumzup Media
  • Vadodara bridge collapse: Death toll rises to 13
  • Stampede concertgoers raise safety concerns after rapper draws huge crowd
  • Liam Payne’s parents share verdict on release of son’s Netflix series filmed before One Direction star’s death

Recent Comments

No comments to show.

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025

Categories

  • Current Affairs
  • Shopping
  • Uncategorized

You may have missed

Three-language policy was withdrawn to avoid law and order problems: Ravindra Chavan | Mumbai News
  • Current Affairs

Three-language policy was withdrawn to avoid law and order problems: Ravindra Chavan | Mumbai News

VedVision HeadLines July 10, 2025
Donald Trump Jr. Invests  Million In Bitcoin Treasury Company Thumzup Media
  • Uncategorized

Donald Trump Jr. Invests $4 Million In Bitcoin Treasury Company Thumzup Media

VedVision HeadLines July 10, 2025
Vadodara bridge collapse: Death toll rises to 13
  • Current Affairs

Vadodara bridge collapse: Death toll rises to 13

VedVision HeadLines July 10, 2025
Stampede concertgoers raise safety concerns after rapper draws huge crowd
  • Current Affairs

Stampede concertgoers raise safety concerns after rapper draws huge crowd

VedVision HeadLines July 10, 2025
Copyright © All rights reserved. | MoreNews by AF themes.