PT-2026-28792 · Unknown · Kusanagi-Mod Security Crs

Hackingrepo

·

Published

2026-01-01

·

Updated

2026-04-19

·

CVE-2026-33691

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OWASP Core Rule Set (CRS) versions prior to 3.3.9 and prior to 4.25.0
Description The OWASP Core Rule Set (CRS) contains a flaw where whitespace padding in filenames can bypass file upload extension checks. This allows the upload of dangerous files such as .php, .phar, .jsp, and .jspx. The affected rules do not normalize whitespace before evaluating the file extension regex, leading to a failure in the dot-extension check. Exploitation is most practical on Windows systems.
Recommendations Upgrade to OWASP CRS version 3.3.9 or 4.25.0.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-33691

Affected Products

Kusanagi-Mod Security Crs