<rss version="2.0"><channel><title>Blogs on Modsecurity Project</title><link>http://modsecurity.org/blog/</link><description>Recent content in Modsecurity Project</description><item><title>About CVE 2026-30923 and 2026-42268</title><link>http://modsecurity.org/20260428/about-cve-2026-30923-and-2026-42268/</link><pubDate>Tue, 28 Apr 2026 00:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30923">CVE-2026-30923</a> and<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42268">CVE-2026-42268</a>, which were published on April 22, 2026, as well as some additional issues that were fixed.</p></description></item><item><title>How Big Is Too Big? A Deep Dive into ModSecurity Request Body Limits</title><link>http://modsecurity.org/20260222/how-big-is-too-big-a-deep-dive-into-modsecurity-request-body-limits/</link><pubDate>Sun, 22 Feb 2026 00:00:00 +0200</pubDate><description><p>Have you ever wondered what exactly the request body limits mean in ModSecurity and how they work?</p></description></item><item><title>Improper error handling: CVE-2025-54571 - 2025 August</title><link>http://modsecurity.org/20250805/improper-error-handling-cve-2025-54571-2025-august/</link><pubDate>Tue, 05 Aug 2025 00:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54571">CVE-2025-54571</a>, which was published on August 5, 2025.</p></description></item><item><title>DoS vulnerability: CVE-2025-52891 - 2025 July</title><link>http://modsecurity.org/20250701/dos-vulnerability-cve-2025-52891-2025-july/</link><pubDate>Tue, 01 Jul 2025 00:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2025-52891">CVE-2025-52891</a>, which was published on July 1, 2025.</p></description></item><item><title>DoS vulnerability: CVE-2025-48866 - 2025 June</title><link>http://modsecurity.org/20250602/dos-vulnerability-cve-2025-48866-2025-june/</link><pubDate>Mon, 02 Jun 2025 00:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2025-48866">CVE-2025-48866</a>, which was published on June 2, 2025.</p></description></item><item><title>ModSecurity-nginx connector - new release: v1.0.4</title><link>http://modsecurity.org/20250521/modsecurity-nginx-connector-new-release-v1.0.4/</link><pubDate>Wed, 21 May 2025 00:00:00 +0200</pubDate><description><p>The OWASP ModSecurity team is pleased to announce the release of ModSecurity-nginx connector version 1.0.4. This version includes a mixture of new features and bug fixes.</p></description></item><item><title>Possible DoS vulnerability: CVE-2025-47947 - 2025 May</title><link>http://modsecurity.org/20250521/possible-dos-vulnerability-cve-2025-47947-2025-may/</link><pubDate>Wed, 21 May 2025 00:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2025-47947">CVE-2025-47947</a>, which was published on May 21, 2025.</p></description></item><item><title>HTML Entity Decoding Regression: CVE-2025-27110 - 2025 February</title><link>http://modsecurity.org/20250225/html-entity-decoding-regression-cve-2025-27110-2025-february/</link><pubDate>Tue, 25 Feb 2025 00:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2025-27110">CVE-2025-27110</a>, which was published on February 25, 2025.</p></description></item><item><title>Use PCRE2 as default - 2025 February</title><link>http://modsecurity.org/20250217/use-pcre2-as-default-2025-february/</link><pubDate>Mon, 17 Feb 2025 00:00:00 +0200</pubDate><description><p>It&rsquo;s time to switch to using the PCRE library.</p></description></item><item><title>About CVE-2024-46292 - 2024 October</title><link>http://modsecurity.org/20241011/about-cve-2024-46292-2024-october/</link><pubDate>Fri, 11 Oct 2024 14:00:00 +0200</pubDate><description><p>We would like to share our take on<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-46292">CVE-2024-46292</a>, which was published on October 9 2024.</p></description></item><item><title>New versions - 2024 September</title><link>http://modsecurity.org/20240903/new-versions-2024-september/</link><pubDate>Tue, 03 Sep 2024 12:00:00 +0200</pubDate><description><p>The OWASP ModSecurity team is pleased to announce the release of versions<a href="https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.8">2.9.8</a> and<a href="https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.13">3.0.13</a>. These versions both include a mixture of new features and bug fixes.</p></description></item><item><title>ModSecurity.org: website available again</title><link>http://modsecurity.org/20240830/modsecurity.org-website-available-again/</link><pubDate>Fri, 30 Aug 2024 14:00:00 +0200</pubDate><description><p>After a long period, the<a href="https://modsecurity.org">modsecurity.org</a> website is available again with renewed content and form.</p></description></item><item><title>Save the date: developers meeting on 5th of June, 2024 - Leuven, Belgium</title><link>http://modsecurity.org/20240523/save-the-date-developers-meeting-on-5th-of-june-2024-leuven-belgium/</link><pubDate>Thu, 23 May 2024 15:15:35 +0200</pubDate><description><p>When the transfer of control took place at the end of January, the interim management stated that they wanted a one-on-one meeting with developers interested in maintaining ModSecurity. It&rsquo;s time. Please save the date: we would like to organize a mini-event on June 5, 2024, where we can meet everyone in person and discuss future tasks. The venue is Leuven, Belgium - the exact location has yet to be determined. We will meet around 13:00 and will leave about 18:00. Stay tuned, register on<a href="https://owasp.slack.com">Slack</a>, where we will try to answer all your questions on the #project-modsecurity channel.</p></description></item><item><title>Modsecurity is arising like Phoenix from the ashes</title><link>http://modsecurity.org/20240422/modsecurity-is-arising-like-phoenix-from-the-ashes/</link><pubDate>Mon, 22 Apr 2024 08:22:35 +0200</pubDate><description><p>The ModSecurity is preparing for the new hand. The announced transfer of custodianship to the OWASP Foundation became a fact,
the project awaits a new adventure! If you add to it that the<a href="https://coreruleset.org/">Core Rule Set</a>, the widespread
set of generic attack detection rules, is already under the roof of OWASP, and both ModSecurity and CRS gather around themselves
vast of security experts, you might come to the conclusion that this can happen without you, can&rsquo;t you?</p></description></item></channel></rss>