High severity7.2GHSA Advisory· Published Jul 16, 2026· Updated Jul 17, 2026
CVE-2026-44982
CVE-2026-44982
Description
CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRequestFromRequest allocated a request body buffer from max(r.ContentLength, 0), so HTTP/1.1 requests using Transfer-Encoding: chunked and HTTP/2 requests without a content-length header produced an empty body and caused WAF rules targeting REQUEST_BODY, BODY_ARGS, ARGS_POST, JSON, or XML to be skipped. This issue is fixed in version 1.7.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/crowdsecurity/crowdsecGo | >= 1.5.0, < 1.7.8 | 1.7.8 |
Affected products
3- Range: >= 1.5.0, <= 1.7.7
- ghsa-coords2 versionspkg:golang/github.com/crowdsecurity/crowdsecpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
>= 1.5.0, < 1.7.8+ 1 more
- (no CPE)range: >= 1.5.0, < 1.7.8
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-rw47-hm26-6wr7ghsaADVISORY
- github.com/crowdsecurity/crowdsec/security/advisories/GHSA-rw47-hm26-6wr7nvdWEB
- github.com/crowdsecurity/crowdsec/commit/3d5c4d9b127091e9063b9b5eb785372a599a4435nvd
- github.com/crowdsecurity/crowdsec/commit/57a793548671e6bbd2cde5562fe87b856ec9c642nvd
- github.com/crowdsecurity/crowdsec/pull/4355nvd
- github.com/crowdsecurity/crowdsec/releases/tag/v1.7.8nvd
News mentions
0No linked articles in our index yet.