Critical severity9.8NVD Advisory· Published Nov 5, 2021· Updated Jun 17, 2026
CVE-2021-35368
CVE-2021-35368
Description
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- OWASP/ModSecurity Core Rule Setdescription
<3.1.2, <3.2.1, <3.3.2+ 1 more
- (no CPE)range: <3.1.2, <3.2.1, <3.3.2
- cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*range: >=3.1.0,<3.1.2
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- coreruleset.org/20210630/cve-2021-35368-crs-request-body-bypass/nvdExploitRelease NotesVendor Advisory
- portswigger.net/daily-swig/lessons-learned-how-a-severe-vulnerability-in-the-owasp-modsecurity-core-rule-set-sparked-much-needed-changenvdExploitThird Party Advisory
- portswigger.net/daily-swig/waf-bypass-severe-owasp-modsecurity-core-rule-set-bug-was-present-for-several-yearsnvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlnvdMailing ListThird Party Advisory
- owasp.org/www-project-modsecurity-core-rule-set/nvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MS5GMNYHFFIBWLJW7N3XAD24SLF3PFZ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IVYUJOKHDEXFTM2CZMEESJ6TZSPVNSSZ/nvd
- security.gentoo.org/glsa/202305-25nvd
News mentions
0No linked articles in our index yet.