CVE-2026-21876CWE-794

OWASP CRS has multipart bypass using multiple content-type parts

Critical · published January 8, 2026

CVSS v3.1
9.3
EPSS
14%
Percentile
96.3
In the wild
Unconfirmed
What it is

🔥 A simple multipart request can slip malicious content past your defenses! A bug in OWASP's core rule set allows a crafty attacker to bypass detection due to variable overwriting. ⚡ Think of this as a restaurant kitchen where a chef keeps replacing the previous order with the latest one on the list—if the last dish looks perfect, they might not notice the sneaky ingredient snuck in earlier! This oversight means an attacker could successfully deliver harmful payloads that could exploit your application without triggering any alarms. Imagine the chaos if your web application doesn't catch malicious charsets hidden within legitimate multipart requests!

Put simply

Think of this as a restaurant kitchen where a chef keeps replacing the previous order with the latest one on the list—if the last dish looks perfect, they might not notice the sneaky ingredient snuck in earlier! Prior to versions 4.22.0 and 3.3.8, a bug in rule 922110 causes capture variables to be overwritten with each iteration of multipart request parts, resulting in only the last valid charset being recognized instead of all parts being checked correctly.

What to do

This oversight means an attacker could successfully deliver harmful payloads that could exploit your application without triggering any alarms. Imagine the chaos if your web application doesn't catch malicious charsets hidden within legitimate multipart requests! Update your OWASP core rule set to version 4.22.0 or 3.3.8 immediately to ensure all multipart request parts are scanned properly. Also, review your existing configurations to mitigate any potential risks from this bug. You've got this! Stay vigilant and patch up—your web application will thank you! 🛡️

The record
Technical detail
CVSS v3.1
9.3 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.14225 · 96.3th percentile
Weakness
CWE-794 · Incomplete Filtering of Multiple Instances of Special Elements
Published
2026-01-08T13:55Z
EPSS history
Timeline
  • 08 JAN 13:55Z
    OWASP CRS has multipart bypass using multiple content-type parts
    cvelistv5