CVE-2024-1019 - CVE House
Back to Database
Status published High CVE-2024-1019

WAF bypass of the ModSecurity v3 release line

Vulnerability Description

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1019

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Andrea Menin @AndreaTheMiddle <https://github.com/theMiddleBlue>
  • Matteo Pace @M4tteoP <https://github.com/M4tteoP>
  • Max Leske <https://github.com/theseion>
  • Ervin Hegedüs @airween <https://github.com/airween>

Affected Vendor

OWASP ModSecurity

View all reports →

Affected Software

ModSecurity
Vulnerable Versions:
3.0.0

Timeline

Official Publish: January 30th, 2024
Last Modified: June 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Weaknesses (CWE)