CVE-2025-48866
ModSecurity has possible DoS vulnerability in sanitiseArg action
Description
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.
How to fix CVE-2025-48866
To remediate CVE-2025-48866, upgrade the affected package to a fixed version below.
- —upgrade to 3.0.12 or later
- —upgrade to 2.9.10 or later
- —upgrade to 2.9.3-3+deb11u4 or later
- —upgrade to 2.9.3-3+deb11u4 or later
Is CVE-2025-48866 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 3.0.12
- from 0, < 2.9.10
- from 0, < 2.9.3-3+deb11u4
- from 0, < 2.9.3-3+deb11u4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (7)
- ADVISORYsecurity-tracker.debian.org/tracker/CVE-2025-48866
- WEBgithub.com/owasp-modsecurity/ModSecurity/commit/3a54ccea62d3f7151bb08cb78d60c5e90b53ca2e
- WEBgithub.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-859r-vvv8-rm8r
- WEBgithub.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-f82j-8pp7-cw2w