Skip to content

Pull requests: owasp-modsecurity/ModSecurity

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Fix memory leak when SecGeoLookupDb loads a database more than once
#3637 opened Sep 19, 2026 by tomsommer Contributor Loading…
Do not keep the @validateSchema parser errors in the operator
#3636 opened Sep 19, 2026 by tomsommer Contributor Loading…
Fix memory leak in setvar when the current value is not numeric
#3635 opened Sep 19, 2026 by tomsommer Contributor Loading…
Fix memory leak of the macro expanded regex in @rx and @rxGlobal
#3634 opened Sep 19, 2026 by tomsommer Contributor Loading…
Fix leak of the ARGS XML parser context on malformed documents
#3633 opened Sep 19, 2026 by tomsommer Contributor Loading…
Fix fd and temporary file leak on truncated multipart payloads
#3632 opened Sep 19, 2026 by tomsommer Contributor Loading…
fix(iis): strip IPv6 zone/scope id from client IP string 2.x Related to ModSecurity version 2.x Platform - IIS
#3631 opened Sep 17, 2026 by A13501350 Loading…
v2: Return HTTP 400 for JSON completion errors without relaxing rejection 2.x Related to ModSecurity version 2.x
#3629 opened Sep 17, 2026 by vortexopenclaw Loading…
CPTAddElement memory leak fix 3.x Related to ModSecurity version 3.x
#3628 opened Sep 16, 2026 by chenuduss Contributor Loading…
Allow SecRuleScript without actions and stop parser state bleed into next rule 3.x Related to ModSecurity version 3.x
#3627 opened Sep 14, 2026 by Copilot AI Loading…
add return value to acmp_build_binary_tree and check it result 3.x Related to ModSecurity version 3.x
#3626 opened Sep 14, 2026 by chenuduss Contributor Loading…
IIS: fix ReadFileChunk latent overflow (allocate m_dwPageSize, not 1) 2.x Related to ModSecurity version 2.x Platform - IIS
#3624 opened Aug 27, 2026 by A13501350 Loading…
IIS: fix dead Host header fallback (r->hostname == NULL can never be true) 2.x Related to ModSecurity version 2.x Platform - IIS
#3622 opened Aug 27, 2026 by A13501350 Loading…
iis: drop chunked Transfer-Encoding when Content-Length is set 2.x Related to ModSecurity version 2.x Platform - IIS
#3618 opened Aug 22, 2026 by A13501350 Loading…
iis: fail closed (HTTP 500) on ModSecurity config load failure 2.x Related to ModSecurity version 2.x Platform - IIS
#3617 opened Aug 22, 2026 by A13501350 Loading…
Fix case-insensitive request header target exclusions 3.x Related to ModSecurity version 3.x
#3616 opened Aug 18, 2026 by TejasButani001 Loading…
Perf/rule remove lookup 3.x Related to ModSecurity version 3.x
#3615 opened Aug 17, 2026 by ziebarthw Loading…
fix: record real response status for IIS audit log F part 2.x Related to ModSecurity version 2.x Platform - IIS
#3613 opened Aug 14, 2026 by A13501350 Loading…
ci: statically link MinGW runtime into x86 fuzzy.dll and add 32-bit pool test 2.x Related to ModSecurity version 2.x windows
#3611 opened Aug 13, 2026 by A13501350 Loading…
test/fuzzer: fix AFL harness input handling and restore it to a compiling state 3.x Related to ModSecurity version 3.x
#3607 opened Aug 1, 2026 by shotintoeternity Loading…
Allow connectors to avoid unused intervention log payload overhead 3.x Related to ModSecurity version 3.x
#3606 opened Aug 1, 2026 by upgle Loading…
fix(windows): pin Conan's CMake generator to match the project's 3.x Related to ModSecurity version 3.x
#3605 opened Jul 28, 2026 by fzipi Collaborator Loading…
2 of 3 tasks
fix(iis): correct InstallModule32/64 CustomAction ID naming swap 2.x Related to ModSecurity version 2.x
#3603 opened Jul 26, 2026 by fzipi Collaborator Loading…
ProTip! Updated in the last three days: updated:>2026-09-16.