OWASP CRS Security Update Advisory (CVE-2026-33691)

OWASP CRS Security Update Advisory (CVE-2026-33691)

Overview A security update has been released to address a vulnerability in OWASP CRS. Users of this product should update to the latest version. Affected Versions OWASP CRS versions prior to 3.3.9. OWASP CRS versions prior to 4.25.0. Vulnerability Details CVE-2026-33691. This is a vulnerability that allows bypassing file extension