https://seclists.org/oss-sec/2026/q2/154: [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability
Published Apr 16, 2026
·Updated
Affected Software
1 affected component
OWASP OWASP Core Rule Set<3.3.9, <4.25.x, <4.8.x
Frequently Asked Questions
1
What is the severity of CVE-2026-33691?
CVE-2026-33691 is classified as a high severity vulnerability due to its potential to bypass security measures in the OWASP Core Rule Set.
2
How does CVE-2026-33691 affect systems?
CVE-2026-33691 allows attackers to bypass unpatched OWASP CRS implementations across various platforms including Windows, Linux, and macOS.
3
How can I fix CVE-2026-33691?
To mitigate CVE-2026-33691, it is recommended to update to the latest version of the OWASP Core Rule Set that includes patches for this vulnerability.
4
What is the impact of exploiting CVE-2026-33691?
Exploiting CVE-2026-33691 can enable attackers to execute unauthorized actions by bypassing security controls in web applications.
5
Is CVE-2026-33691 related to any other vulnerabilities?
Yes, CVE-2026-33691 is related to CVE-2015-10138, as it can allow similar exploits when CRS is unpatched.