
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-104259 is a WAF rule bypass and out-of-bounds read vulnerability in ModSecurity's removeComments transformation function. The flaw causes the inplace() function in src/actions/transformations/remove_comments.cc (v3) and msre_fn_removeComments_execute in apache2/re_tfns.c (v2) to fail stripping adjacent comments, allowing attackers to smuggle SQLi/XSS payloads through comment-stripping-dependent WAF rules. Affected versions are ModSecurity v3 ≤ 3.0.16 and v2 ≤ 2.9.14; patched versions are 3.0.17 and 2.9.15 respectively. The Debian modsecurity and modsecurity-apache packages have no patch available as of the advisory date. It carries a CVSS v3.1 score of 5.4 (Moderate) (GitHub Advisory).
The root cause is an always-incorrect control flow implementation (CWE-670) in the comment-removal logic. When a comment closer (*/) is encountered, the code increments the index by 2 and immediately copies the next character to output without re-evaluating it as a potential new comment opener. This means input like /*A*//*B*/ produces /*B*/ instead of an empty string, allowing adjacent inline comments to survive transformation. Additionally, when a comment closer is the last content in the input buffer, i += 2 (or i += 3 for --> closers) can make i == input_len before the subsequent dereference, resulting in a one-byte out-of-bounds read. The identical pattern exists in both the v2 and v3 codebases (GitHub Advisory).
Successful exploitation enables two distinct impacts: a WAF rule bypass allowing attackers to deliver SQLi or XSS payloads (e.g., /**/UNION/**/SELECT/**/) that survive t:removeComments transformation and reach downstream rule matching or the backend application unmodified; and a one-byte out-of-bounds read from the transformed buffer, which could theoretically leak memory content or contribute to instability. The bypass impact is the more operationally significant, as it undermines the integrity of comment-stripping-dependent detection rules and exposes protected applications to injection attacks (GitHub Advisory).
A proof-of-concept was confirmed by the reporter (HEXER365), who compiled and ran the actual remove_comments.cc object code to demonstrate that input /*A*//*B*/ produces /*B*/ instead of an empty string. No exploit kits or in-the-wild exploitation have been reported as of the advisory date. The CVE status is listed as "Reserved" and no EPSS score or CISA KEV catalog entry is currently available. Exploitation requires no authentication or user interaction but does require high attack complexity, as the attacker must craft payloads specifically targeting rules that rely on t:removeComments (GitHub Advisory, Tenable).
t:removeComments transformation for SQLi or XSS detection./**/UNION/**/SELECT/**/1,2,3-- or <scr/**/ipt>alert(1)</scr/**/ipt>.removeComments transformation fails to strip the second (and subsequent) adjacent comments, so the obfuscated payload survives rule matching and is forwarded to the backend application unmodified./**/UNION/**/SELECT/**/, /**/OR/**/1=1/**/, or similar obfuscated injection strings in query parameters or POST bodies./*...*//*...*/) that were not blocked or flagged by comment-stripping rules; absence of expected rule triggers for known SQLi/XSS patterns when inline comments are present.Upgrade ModSecurity v3 to version 3.0.17 and ModSecurity v2 to version 2.9.15, which contain the corrected comment-removal logic. For Debian users, note that the vendor has indicated no patch is currently available for the modsecurity and modsecurity-apache packages; administrators should monitor Debian security advisories for updates. As a workaround, consider supplementing or replacing t:removeComments-dependent rules with alternative detection logic that does not rely solely on comment stripping, or add custom rules to detect adjacent comment patterns (/\*.*\*/\s*/\*) before transformation (GitHub Advisory, Tenable).
The vulnerability was reported by researcher HEXER365 and published as a GitHub Security Advisory (GHSA-qrch-pjfr-9g47) by the OWASP ModSecurity maintainers on September 30, 2026. Tenable has published a Nessus plugin (362950) to detect affected installations. No broader media coverage or notable social media discussion has been identified as of the advisory date.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."