ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
Loading...
Loading...
Score 5.3 from GitHub Security Advisory published 2022-05-24. NVD baseline CVSS 5.3; sources differ by 0.0.
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
May 6, 2021
July 3, 2025
See which npm, PyPI, Go, and Maven packages are affected by CVE-2019-25043
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.