ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade mod_securityUpgrade mod_security-mlogcUpgrade mod_security-debuginfo | Jun 13, 2025 | Jun 2, 2025 |
| Amazon_linux_2023 | — | Upgrade mod_security-debugsourceUpgrade mod_security-debuginfoUpgrade mod_security-mlogcUpgrade mod_securityUpgrade mod_security-mlogc-debuginfo | Jun 24, 2025 | Jun 2, 2025 |
| Debian | — | Upgrade modsecurity-apache | Jun 4, 2025 | Jun 2, 2025 |
| Freebsd | — | Upgrade ap24-mod_security | Jun 8, 2025 | Jun 6, 2025 |
| Oracle_linux | — | Upgrade mod_security-mlogcUpgrade mod_security | Aug 6, 2025 | Jun 2, 2025 |
| Redhat_linux | — | Upgrade mod_security-mlogcUpgrade mod_security-debuginfoNo solution existsUpgrade mod_security-debugsourceUpgrade mod_security-mlogc-debuginfoUpgrade mod_security | Jul 9, 2025 | Jun 2, 2025 |
| Rocky_linux | — | Upgrade mod_security-debuginfoUpgrade mod_security-mlogc-debuginfoUpgrade mod_security-mlogcUpgrade mod_security-debugsourceUpgrade mod_security | Feb 9, 2026 | Oct 4, 2025 |
| Suse | — | Upgrade apache2-mod_security2 | Dec 5, 2025 | Aug 11, 2025 |
| Ubuntu | — | Upgrade libapache2-mod-security2Upgrade libapache2-modsecurity (Ubuntu Pro)Upgrade libapache2-mod-security2 (Ubuntu Pro) | Jun 17, 2025 | Jun 2, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub