Skip to content
Critical Memory Leak and Disclosure in nginx-mod-modsecurity

Critical Memory Leak and Disclosure in nginx-mod-modsecurity

First seen 4 Jan 2026, 10:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The ModSecurity-nginx connector, essential for communication between nginx and libmodsecurity, has been identified with critical vulnerabilities leading to memory leak and disclosure risks. Affected versions include those in Fedora 42 and Fedora 43, with updates provided in nginx version 1.28.1 released on December 23, 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2025-53859 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed