OWASP CRS Security Update Advisory (CVE-2026-33691)

OWASP CRS Security Update Advisory (CVE-2026-33691)

Overview

A security update has been released to address a vulnerability in OWASP CRS. Users of this product should update to the latest version.

Affected Versions

  • OWASP CRS versions prior to 3.3.9.
  • OWASP CRS versions prior to 4.25.0.

Vulnerability Details

  • CVE-2026-33691.
  • This is a vulnerability that allows bypassing file extension validation when uploading files due to whitespace padding in file names.
  • This vulnerability allows attackers to bypass file extension checks during file uploads.

Mitigation

Users should update OWASP CRS to the latest version with the Vulnerability Patch, following the instructions on the reference site.

Reference

[1] Whitespace padding in filenames bypasses file upload extension checks. Https://github.Com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w.