-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Issues: owasp-modsecurity/ModSecurity
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Remove possiblity to disable early-blocking processing
2.x
Related to ModSecurity version 2.x
#3362
opened Apr 17, 2025 by
arminabf
feat: improved XMLArgs processing
2.x
Related to ModSecurity version 2.x
#3358
opened Apr 7, 2025 by
airween
Loading…
Feature Request (v2): Add support for macro expansion for ipMatch operator
2.x
Related to ModSecurity version 2.x
#3332
opened Jan 21, 2025 by
EsadCetiner
base64Decode behaviour against payload which contain + and /
2.x
Related to ModSecurity version 2.x
#3327
opened Jan 10, 2025 by
touchweb-vincent
Transformation Related to ModSecurity version 2.x
3.x
Related to ModSecurity version 3.x
hexDecode
should not allow badly encoded inputs, or documentation should be updated
2.x
#3325
opened Jan 9, 2025 by
fzipi
ModSecurity 2.9.7 install on Windows is blocking access to some local URL
2.x
Related to ModSecurity version 2.x
#3323
opened Jan 8, 2025 by
adrianglendinningGPI
Post-use evaluation feedback
2.x
Related to ModSecurity version 2.x
#3320
opened Jan 6, 2025 by
zhouhao425
I'm having trouble importing the modsecurity module into nginx.
2.x
Related to ModSecurity version 2.x
#3317
opened Dec 23, 2024 by
MuhammetAliKara
Drop YAJL dependency
2.x
Related to ModSecurity version 2.x
3.x
Related to ModSecurity version 3.x
#3308
opened Nov 26, 2024 by
mikelolasagasti
Segmentation fault in ModSecurity 2.9 for Apache
2.x
Related to ModSecurity version 2.x
#3300
opened Nov 13, 2024 by
vizovitin
Operator @rx has different flags in two engines
2.x
Related to ModSecurity version 2.x
#3295
opened Nov 7, 2024 by
airween
Unicode encoding (table) problem on engine level leading to CRS false positives (U+062F and U+D8AF resolving to slash)
2.x
Related to ModSecurity version 2.x
3.x
Related to ModSecurity version 3.x
#3294
opened Nov 4, 2024 by
dune73
using iptables marks or ipsets
2.x
Related to ModSecurity version 2.x
#3289
opened Oct 29, 2024 by
f1-outsourcing
Don't explicitly use files for mutex creation
2.x
Related to ModSecurity version 2.x
Platform - Apache
#3285
opened Oct 22, 2024 by
marcstern
Loading…
Inconsistent use of SecArgumentsLimit in Recommended Rules
2.x
Related to ModSecurity version 2.x
config
Related to default config
#3261
opened Sep 25, 2024 by
studersi
fix: Handle "filename*" field in MP header
2.x
Related to ModSecurity version 2.x
#3239
opened Aug 25, 2024 by
airween
Loading…
Discussion of the new XML processing feature
2.x
Related to ModSecurity version 2.x
#3178
opened Jun 28, 2024 by
airween
[modsecurity.conf-recommended] align processing on request & response for json
2.x
Related to ModSecurity version 2.x
config
Related to default config
#3175
opened Jun 24, 2024 by
fzipi
Problem about proxy action
2.x
Related to ModSecurity version 2.x
Platform - Apache
#3170
opened Jun 12, 2024 by
prince-java
Apache: Short Lingering Close
2.x
Related to ModSecurity version 2.x
Platform - Apache
#3143
opened May 15, 2024 by
studersi
@rbl operator does not support IPv6
2.x
Related to ModSecurity version 2.x
3.x
Related to ModSecurity version 3.x
bug
It is a confirmed bug
duplicate
Ops. Somebody else already hit that bump
🥇 good first issue
#3131
opened Apr 24, 2024 by
airween
Incorrect utf8toUnicode transformation for 00xx
2.x
Related to ModSecurity version 2.x
#3129
opened Apr 23, 2024 by
marcstern
feat: Allow regular expressions in ctl:ruleRemoveTargetByX variable names II.
2.x
Related to ModSecurity version 2.x
do not merge
#3121
opened Apr 16, 2024 by
airween
Loading…
Feature request: Limit the number of rules processed per request
2.x
Related to ModSecurity version 2.x
#3112
opened Mar 25, 2024 by
no-sec-marko
Previous Next
ProTip!
Find all open issues with in progress development work with linked:pr.