CVE-2025-48866: ModSecurity has possible DoS vulnerability in sanitiseArg action
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The sanitiseArg (and sanitizeArg - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the sanitiseArg (or sanitizeArg) action.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48866?
CVE-2025-48866 has been identified as a denial of service vulnerability.
How do I fix CVE-2025-48866?
To remediate CVE-2025-48866, upgrade to ModSecurity version 2.9.10 or later.
Which versions of ModSecurity are affected by CVE-2025-48866?
ModSecurity versions prior to 2.9.10 are vulnerable to CVE-2025-48866.
What is the nature of the vulnerability in CVE-2025-48866?
CVE-2025-48866 involves a denial of service vulnerability related to the sanitisation functions in ModSecurity.
Can CVE-2025-48866 be exploited remotely?
Yes, CVE-2025-48866 can potentially be exploited by an attacker remotely to trigger a denial of service condition.