PT-2026-28792 · Unknown · Kusanagi-Mod Security Crs
Hackingrepo
·
Published
2026-01-01
·
Updated
2026-04-19
·
CVE-2026-33691
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OWASP Core Rule Set (CRS) versions prior to 3.3.9 and prior to 4.25.0
Description
The OWASP Core Rule Set (CRS) contains a flaw where whitespace padding in filenames can bypass file upload extension checks. This allows the upload of dangerous files such as .php, .phar, .jsp, and .jspx. The affected rules do not normalize whitespace before evaluating the file extension regex, leading to a failure in the dot-extension check. Exploitation is most practical on Windows systems.
Recommendations
Upgrade to OWASP CRS version 3.3.9 or 4.25.0.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kusanagi-Mod Security Crs