CVE-2021-42717
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
Published:Dec 7, 2021
Last Modified:Jul 3, 2025
EPS:Dec 7, 2021
EPSS Score:0.02217
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
F5
Product
Nginx Modsecurity Waf
F5
Nginx Modsecurity Waf
Vendor
Oracle
Product
Http Server
Oracle
Http Server
Vendor
Oracle
Product
Zfs Storage Appliance Kit
Oracle
Zfs Storage Appliance Kit
Vendor
Owasp
Product
Modsecurity
Owasp
Modsecurity
Vendor
Trustwave
Product
Modsecurity
Trustwave
Modsecurity
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
