← Vulnerability feed

Vulnerability record · CVE-2025-27110 · published 25 February 2025

CVE-2025-27110: Trustwave modsecurity vulnerability

Trustwave · Modsecurity

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode encoded HTML entities if they contains leading zeroes. Version 3.0.14 contains a fix. No known workarounds are available.

7.9 CVSS 4.0 High EPSS 0.49% · top 60.7% CWE-172 · CWE-172
7.9CVSS 4.0 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode encoded HTML entities if they contains leading zeroes. Version 3.0.14 contains a fix. No known workarounds are available.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27110 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2025-47947Trustwave modsecurity vulnerabilityModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are…EPSS 0.60%7.5CVE-2024-46292Trustwave modsecurity classic buffer overflow vulnerabilityA buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NO…EPSS 0.82%7.5CVE-2023-24021Trustwave modsecurity vulnerabilityIncorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on…EPSS 0.91%7.5CVE-2022-48279Owasp modsecurity interpretation conflict vulnerabilityIn ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE…EPSS 1.2%7.5CVE-2021-42717Owasp modsecurity vulnerabilityModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in th…EPSS 3.1%7.5CVE-2013-1915Trustwave modsecurity xml external entity (xxe) vulnerabilityModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU a…EPSS 4.2%5.0CVE-2013-5705Trustwave modsecurity vulnerabilityapache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked…EPSS 2.7%5.0CVE-2013-2765Trustwave modsecurity null pointer dereference vulnerabilityThe ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, proces…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2025-27110), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.