High severity7.5NVD Advisory· Published Oct 9, 2024· Updated Jun 17, 2026
CVE-2024-46292
CVE-2024-46292
Description
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:trustwave:modsecurity:3.0.12:*:*:*:*:*:*:*
- modsecurity/modsecuritydescription
- Range: <3.0.12
- osv-coords2 versions
>= 3.0.12, < 3.0.13+ 1 more
- (no CPE)range: >= 3.0.12, < 3.0.13
- (no CPE)range: >= 3.0.12, <= 3.0.12
Patches
Vulnerability mechanics
References
3- github.com/owasp-modsecurity/ModSecurity/blob/v3/master/README.mdnvdVendor Advisory
- modsecurity.org/20241011/about-cve-2024-46292-2024-october/nvdVendor Advisory
- github.com/yoloflz101/yoloflz/blob/main/README.mdnvdBroken Link
News mentions
0No linked articles in our index yet.