Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-62231.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-62231
Upstream
Published
2025-06-02T16:15:29Z
Modified
2026-04-01T05:20:01.762839Z
Summary
CVE-2025-48866 affecting package mod_security 2.9.7-8
Details

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The sanitiseArg (and sanitizeArg - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the sanitiseArg (or sanitizeArg) action.

References

Affected packages

Azure Linux:3 / mod_security

Package

Name
mod_security
Purl
pkg:rpm/azure-linux/mod_security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.9.7-8

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-62231.json"