{
  "threat_severity" : "Important",
  "public_date" : "2025-05-21T22:08:31Z",
  "bugzilla" : {
    "description" : "modsecurity: ModSecurity Has Possible DoS Vulnerability",
    "id" : "2367903",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2367903"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-1050",
  "details" : [ "ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action. A patch is available at pull request 3389 and expected to be part of version 2.9.9. No known workarounds are available.", "A flaw was found in the mod_security2 Apache2 module. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case. In stable released versions, when the payload's content type is `application/json`, at least one rule performs a `sanitiseMatchedBytes` action, a security control that automatically cleans or neutralizes specific patterns of potentially harmful data that prevents malicious input from reaching systems or sensitive information from leaking." ],
  "affected_release" : [ {
    "product_name" : "JBoss Core Services for RHEL 8",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el8",
    "package" : "jbcs-httpd24-httpd-0:2.4.62-8.el8jbcs"
  }, {
    "product_name" : "JBoss Core Services for RHEL 8",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el8",
    "package" : "jbcs-httpd24-mod_http2-0:2.0.29-5.el8jbcs"
  }, {
    "product_name" : "JBoss Core Services for RHEL 8",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el8",
    "package" : "jbcs-httpd24-mod_jk-0:1.2.50-9.redhat_1.el8jbcs"
  }, {
    "product_name" : "JBoss Core Services for RHEL 8",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el8",
    "package" : "jbcs-httpd24-mod_md-1:2.4.28-10.el8jbcs"
  }, {
    "product_name" : "JBoss Core Services for RHEL 8",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el8",
    "package" : "jbcs-httpd24-mod_proxy_cluster-0:1.3.22-4.el8jbcs"
  }, {
    "product_name" : "JBoss Core Services for RHEL 8",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el8",
    "package" : "jbcs-httpd24-mod_security-0:2.9.6-11.el8jbcs"
  }, {
    "product_name" : "JBoss Core Services on RHEL 7",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el7",
    "package" : "jbcs-httpd24-httpd-0:2.4.62-8.el7jbcs"
  }, {
    "product_name" : "JBoss Core Services on RHEL 7",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el7",
    "package" : "jbcs-httpd24-mod_http2-0:2.0.29-5.el7jbcs"
  }, {
    "product_name" : "JBoss Core Services on RHEL 7",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el7",
    "package" : "jbcs-httpd24-mod_jk-0:1.2.50-9.redhat_1.el7jbcs"
  }, {
    "product_name" : "JBoss Core Services on RHEL 7",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el7",
    "package" : "jbcs-httpd24-mod_md-1:2.4.28-10.el7jbcs"
  }, {
    "product_name" : "JBoss Core Services on RHEL 7",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el7",
    "package" : "jbcs-httpd24-mod_proxy_cluster-0:1.3.22-4.el7jbcs"
  }, {
    "product_name" : "JBoss Core Services on RHEL 7",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13680",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1::el7",
    "package" : "jbcs-httpd24-mod_security-0:2.9.6-11.el7jbcs"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-06-11T00:00:00Z",
    "advisory" : "RHSA-2025:8844",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "mod_security-0:2.9.6-2.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Advanced Update Support",
    "release_date" : "2025-06-09T00:00:00Z",
    "advisory" : "RHSA-2025:8626",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.2",
    "package" : "mod_security-0:2.9.2-8.el8_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2025-06-09T00:00:00Z",
    "advisory" : "RHSA-2025:8627",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "mod_security-0:2.9.2-9.el8_4.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2025-06-05T00:00:00Z",
    "advisory" : "RHSA-2025:8605",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "mod_security-0:2.9.2-9.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
    "release_date" : "2025-06-05T00:00:00Z",
    "advisory" : "RHSA-2025:8605",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.6",
    "package" : "mod_security-0:2.9.2-9.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
    "release_date" : "2025-06-05T00:00:00Z",
    "advisory" : "RHSA-2025:8605",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.6",
    "package" : "mod_security-0:2.9.2-9.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2025-06-09T00:00:00Z",
    "advisory" : "RHSA-2025:8674",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "mod_security-0:2.9.6-1.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2025-06-09T00:00:00Z",
    "advisory" : "RHSA-2025:8674",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "mod_security-0:2.9.6-1.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-06-11T00:00:00Z",
    "advisory" : "RHSA-2025:8837",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "mod_security-0:2.9.6-2.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2025-06-11T00:00:00Z",
    "advisory" : "RHSA-2025:8922",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "mod_security-0:2.9.3-12.el9_0.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2025-06-11T00:00:00Z",
    "advisory" : "RHSA-2025:8937",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "mod_security-0:2.9.6-1.el9_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Extended Update Support",
    "release_date" : "2025-06-11T00:00:00Z",
    "advisory" : "RHSA-2025:8917",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.4",
    "package" : "mod_security-0:2.9.6-1.el9_4.1"
  }, {
    "product_name" : "Red Hat JBoss Core Services 2.4.62.SP1",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13681",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1",
    "package" : "jbcs-httpd24-mod_security"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "mod_security_crs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "mod_security_crs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "mod_security_crs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-47947\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-47947\nhttps://github.com/owasp-modsecurity/ModSecurity/pull/3389\nhttps://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-859r-vvv8-rm8r" ],
  "name" : "CVE-2025-47947",
  "csaw" : false
}