Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Studersi

#33663of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2025-22442
7.8
2025-05-21
Unknown · Modsecurity · CVE-2025-47947
**Name of the Vulnerable Software and Affected Versions** ModSecurity versions up to and including 2.9.8 **Description** ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. The issue arises when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action, leading to a denial of service. **Recommendations** For versions up to and including 2.9.8, update to version 2.9.9, which is expected to include the patch available at pull request 3389. As a temporary workaround, consider disabling rules that perform the `sanitiseMatchedBytes` action when the payload's content type is `application/json` until a patch is available.