CVE-2025-54571
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-06

Last updated on: 2025-11-03

Assigner: GitHub, Inc.

Description
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP response’s Content-Type, which could lead to several issues depending on the HTTP scenario. For example, we have demonstrated the potential for XSS and arbitrary script source code disclosure in the latest version of mod_security2. This issue is fixed in version 2.9.12.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-06
Last Modified
2025-11-03
Generated
2026-05-06
AI Q&A
2025-08-06
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
owasp modsecurity From 2.0.0 (inc) to 2.9.12 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-252 The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in ModSecurity versions 2.9.11 and below allows an attacker to override the HTTP response's Content-Type header. This can lead to various issues depending on the HTTP scenario, including potential cross-site scripting (XSS) attacks and arbitrary script source code disclosure.


How can this vulnerability impact me? :

The vulnerability can impact you by enabling attackers to perform cross-site scripting (XSS) attacks or disclose arbitrary script source code, which can compromise the security of your web applications and potentially expose sensitive information or allow malicious code execution.


What immediate steps should I take to mitigate this vulnerability?

Upgrade ModSecurity to version 2.9.12 or later, as this version contains the fix for the vulnerability that allows an attacker to override the HTTP response's Content-Type.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart