CVE-2019-25043: Owasp Modsecurity
Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
Affected products
- Owasp Modsecurity: from 3.0.0, before 3.0.4 (fixed in 3.0.4)
Published 2021-05-06. Last modified 2026-06-17.