Skip to content

OWASP CRS Vulnerability Allows Attackers to Bypass Charset Validation

Cybersecuritynews •Abinaya • January 9, 2026

A critical vulnerability in the OWASP Core Rule Set (CRS) has been discovered that allows attackers to bypass important security protections designed to prevent charset-based attacks. The vulnerability, tracked as CVE-2026-21876, affects rule 922110 and carries a severity score of 9.3 (CRITICAL). OWASP CRS Vulnerability Rule 922110 is designed to block dangerous character encodings, such […]

Extracted Entities

Platforms (1)