First published: Tue Feb 25 2025(Updated: )
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode encoded HTML entities if they contains leading zeroes. Version 3.0.14 contains a fix. No known workarounds are available.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trustwave ModSecurity | =3.0.13 | |
ModSecurity |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27110 is classified as a medium severity vulnerability.
To fix CVE-2025-27110, upgrade Libmodsecurity to version 3.0.14 or later.
CVE-2025-27110 affects Libmodsecurity3 version 3.0.13.
CVE-2025-27110 is a bug in the Libmodsecurity component of ModSecurity that can impact web traffic processing.
CVE-2025-27110 was reported in 2025, associated with the release of Libmodsecurity3 version 3.0.13.