CVE-2026-42268: ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::outofrange) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42268?
CVE-2026-42268 is classified as a moderate severity vulnerability due to the potential for a denial of service through an unhandled exception.
How do I fix CVE-2026-42268?
To remediate CVE-2026-42268, upgrade ModSecurity to version 3.0.15 or later.
What systems are affected by CVE-2026-42268?
CVE-2026-42268 affects ModSecurity versions from 3.0.0 to before 3.0.15 on Apache, IIS, and Nginx servers.
What types of operators are involved in CVE-2026-42268?
CVE-2026-42268 involves the @verifySSN, @verifyCPF, and @verifySVNR operators.
Is CVE-2026-42268 applicable to older ModSecurity versions?
Yes, CVE-2026-42268 specifically affects ModSecurity versions ranging from 3.0.0 up to but not including 3.0.15.