Critical Memory Leak and Disclosure in nginx-mod-modsecurity

Critical Memory Leak and Disclosure in nginx-mod-modsecurity

First seen 4 Jan 2026, 10:39 UTC Linuxsecurity 33.7

Article Content

Browse articles
ThreatCluster

The ModSecurity-nginx connector, essential for communication between nginx and libmodsecurity, has been identified with critical vulnerabilities leading to memory leak and disclosure risks. Affected versions include those in Fedora 42 and Fedora 43, with updates provided in nginx version 1.28.1 released on December 23, 2025.