owasp-modsecurity/ModSecurity
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.
C++Apache-2.0
Issues
- 2
Operator @fuzzyHash don't work as expected
#3462 opened by capy3ra - 4
libmodsecurity3: not returning 403 on response phases
#3461 opened by EsadCetiner - 5
- 8
ModSecurity v2.9.12 “Skipping request since there is nowhere to write to” despite valid SecAuditLog configuration
#3446 opened by tinhutins - 3
SecRule with SSL_CLIENT failed
#3459 opened by nono303 - 3
legacy pcre being preferred over pcre2 during ./configure
#3453 opened by Vitadek - 1
- 9
IP Collection not working properly
#3416 opened by Greentears - 1
2.x standalone fails to link since ap_map_http_request_error() is not exported as APR function
#3451 opened by kabe-gh - 2
Build fails because of missing `library/base64.c` when using Mbed TLS 4.x — Is support planned?
#3450 opened by TheophileDiot - 13
Event message with description "Invalid function" in the Windows Application Event Log
#3408 opened by skvoboo-gh - 3
- 1
Sanitizer reports (ASAN, UBSAN)
#3448 opened by chenuduss - 5
Compile ModSecurity on Windows cannot build dll file
#3444 opened by YornSokha - 3
[Feature Request] Mod_Security as a Webmin Menu
#3445 opened by sshcli - 4
- 1
- 5
Performance issues with ModSecurity2/Alpine/PCRE2
#3409 opened by as-rail - 9
SecAuditLogRelevantStatus conf is not working?
#3433 opened by opsmeta - 2
2.9.12 installer
#3440 opened by perlsol - 4
running `./build.sh` on Ubuntu 24.04 gives warnings: "warning: wildcard utils/*.h: non-POSIX variable name"
#3435 opened by Danrancan - 10
Stack overflow in pcre.dll
#3436 opened by skvoboo-gh - 2
- 14
Unable to parse absolute Windows path as value of modsecurity.conf directive
#3429 opened by skvoboo-gh - 4
>=v3.0.13 release for ubuntu 22.04
#3423 opened by imgurbot12 - 16
Semantic of MATCHED_VARS / MATCHED_VARS_NAMES
#3382 opened by mirkodziadzka-avi - 2
- 5
ModSecurity2 v2.9.11 not working on RHEL 7 due to undefined symbol: pcre2_set_depth_limit
#3417 opened by friesoft - 1
request on iis with more than 999 characters single value in cookie are getting blocked and no specific rule to fix
#3413 opened by HumanUndead - 5
Error in msc_status_engine.c
#3410 opened by Greentears - 10
Enhancement: Extend CI workflow to test library detection with manually compiled dependencies
#3407 opened by JustCoding247 - 2
ModSecurity 3.0.14 configure script fails to detect lib64-installed YAJL, LMDB, and PCRE2
#3404 opened by JustCoding247 - 2
- 6
Audit log no longer written since update to 3.0.14
#3402 opened by mpitzl - 4
Quotation Mark Formatting in ModSecurity Logs: Is the Use of Backticks and Single Quotes Correct?
#3369 opened by wRkA - 21
- 11
Remove possiblity to disable early-blocking processing
#3362 opened by arminabf - 7
modsecurity.conf last file
#3367 opened by Max131412 - 14
2,9,7 Appl Error 1000 in w3wp.exe Module ucrtbase.dll
#3397 opened by FrankWarius - 5
Outdated product version in the MSI installer
#3399 opened by skvoboo-gh - 8
- 2
- 6
Readme instructions for IIS installation
#3370 opened by tbremard - 1
Recommended Location, permissions, and ownership of "SecTmpDir" and "SecDataDir"
#3384 opened by Danrancan - 3
modsecurity.digitalwave.hu no release file
#3381 opened by rishabhAjay - 3
Standalone module no longer logs client IP to error log
#3373 opened by RedXanadu - 8
Behavior change in regex macro expansion from 2.9.7 to 2.9.8 affecting CRS 3.2.x and 3.3.x
#3380 opened by dune73 - 1
Duplicate Server headers in Audit Log when using more_set_headers or more_clear_headers in Nginx
#3368 opened by wRkA - 3
Wiki image link broken
#3366 opened by stoecker - 3