CVE-2019-25043: Owasp Modsecurity

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.

Affected products

  • Owasp Modsecurity: from 3.0.0, before 3.0.4 (fixed in 3.0.4)

Published 2021-05-06. Last modified 2026-06-17.