https://seclists.org/oss-sec/2026/q2/173: [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability
Published Apr 18, 2026
·Updated
Affected Software
1 affected component
OWASP Core Rule Set (CRS)<3.3.9, <4.25.x, <4.8.x
Frequently Asked Questions
1
What is the severity of CVE-2026-33691?
CVE-2026-33691 is considered a critical vulnerability due to its potential to disable ModSecurity WAF.
2
How do I fix CVE-2026-33691?
To fix CVE-2026-33691, you should update your OWASP Core Rule Set to the latest version and ensure that ModSecurity is properly configured.
3
What systems are impacted by CVE-2026-33691?
CVE-2026-33691 primarily affects systems using the OWASP Core Rule Set in conjunction with ModSecurity.
4
What kind of attack can exploit CVE-2026-33691?
CVE-2026-33691 can be exploited through whitespace padding attacks that potentially bypass web application firewall protections.
5
Is CVE-2026-33691 under active exploitation?
As of now, there have been indications that CVE-2026-33691 may be actively exploited in the wild.