CVE-2022-39956
ModSecurity vulnerability analysis and mitigation

Overview

The OWASP ModSecurity Core Rule Set (CRS) was affected by a partial rule set bypass vulnerability (CVE-2022-39956) discovered in September 2022. The vulnerability affects HTTP multipart requests where payloads using specific character encoding schemes via the Content-Type or Content-Transfer-Encoding multipart MIME header fields could bypass web application firewall detection. The vulnerability impacted legacy CRS versions 3.0.x and 3.1.x, as well as versions 3.2.1 and 3.3.2 (Core Rule Set).

Technical details

The vulnerability allows attackers to submit payloads that use character encoding schemes through Content-Type or deprecated Content-Transfer-Encoding multipart MIME header fields that bypass inspection by the web application firewall engine and rule set. The CVSS v3.1 base score is 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) according to NVD assessment, while the Swiss Government Common Vulnerability Program rated it as 7.3 HIGH (NVD).

Impact

When exploited, the vulnerability allows multipart payloads to bypass detection completely. Any backend system that supports these encoding schemes could potentially be exploited, as the WAF would fail to inspect the encoded content. This creates a significant security gap where malicious content could be transmitted without detection (Core Rule Set).

Exploitability

The vulnerability requires no special privileges or user interaction to exploit, making it highly exploitable. The attack can be performed remotely by sending specially crafted HTTP requests with specific MIME header fields. The vulnerability was discovered during the Intigriti 1337UP0522 WAF Promotion Event by security researcher @terjanq (Jan Gora) (Core Rule Set).

Mitigation and workarounds

Users and integrators are advised to upgrade to CRS versions 3.2.2 and 3.3.3 or later. Additionally, the mitigation requires installation of ModSecurity version 2.9.6 or 3.0.8 or later. Without the latest ModSecurity version, the vulnerability cannot be mitigated, and ModSecurity will refuse to start with error message 'Error creating rule: Unknown variable: MULTIPART_PART_HEADERS'. As a temporary workaround, users can disable/remove the rule file REQUEST-922-MULTIPART-ATTACK.conf, though this is not recommended as it leaves the system vulnerable (Core Rule Set, Debian LTS).

Additional resources


SourceThis report was generated using AI

Related ModSecurity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-52747HIGH8.6
  • ModSecurity logoModSecurity
  • mod_security.src
NoYesJul 10, 2026
CVE-2026-42268HIGH8.2
  • ModSecurity logoModSecurity
  • mod_security.src
NoYesMay 12, 2026
CVE-2026-30923HIGH8.2
  • ModSecurity logoModSecurity
  • mod_security
NoYesMay 05, 2026
CVE-2025-54571MEDIUM6.9
  • ModSecurity logoModSecurity
  • apache2-mod_security2
NoYesAug 06, 2025
CVE-2026-52761MEDIUM5.3
  • ModSecurity logoModSecurity
  • mod_security-mlogc
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management