CVE-2026-52761CWE-467

ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture

Medium · published July 10, 2026

CVSS v3.1
5.8
EPSS
0%
Percentile
34.3
In the wild
Unconfirmed
What it is

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.

The record
Technical detail
CVSS v3.1
5.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00411 · 34.3th percentile
Weakness
CWE-467 · Use of sizeof() on a Pointer Type
Published
2026-07-10T21:40Z
EPSS history
Timeline
  • 10 JUL 21:40Z
    ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture
    cvelistv5