FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

ModSecurity -- Possible DoS Vulnerability

Affected packages
ap24-mod_security < 2.9.8

Details

VuXML ID a372abb0-3d3c-11f0-86e7-b42e991fc52e
Discovery 2025-05-21
Entry 2025-05-30

security-advisories@github.com reports:

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action. A patch is available at pull request 3389 and expected to be part of version 2.9.9. No known workarounds are available.

References

CVE Name CVE-2025-47947
URL https://nvd.nist.gov/vuln/detail/CVE-2025-47947