OWASP CRS v4.30.0 and v4.25.2 LTS Ship Three Critical WAF Bypass Fixes

Published by

The OWASP Core Rule Set (CRS) released versions v4.30.0 and v4.25.2 (LTS) on October 2, 2026, which included three critical fixes for web application firewall (WAF) bypass vulnerabilities. These updates addressed issues related to path-based command injection in RCE rules, a case-sensitivity bug in charset allow-lists, and a multipart charset shadowing trick that could allow attackers to bypass encoding checks. In addition to the security fixes, v4.30.0 introduced new detection capabilities for various tools and command usages, while also repairing a response-skipping flag that previously affected rule evaluations. Users of affected versions are advised to upgrade promptly or apply specific workarounds outlined in the advisories to mitigate the identified vulnerabilities



OWASP CRS v4.30.0 and v4.25.2 LTS Ship Three Critical WAF Bypass Fixes

The OWASP Core Rule Set released v4.30.0 and v4.25.2 (LTS) within thirteen minutes of each other on 2 October 2026, pushing three security bypass fixes to both its newest feature line and its older LTS branch. The fixes close a path-based command injection gap in the RCE rules (GHSA-575j-qr6p-9763), a case-sensitivity bug that left the charset allow-list inert at default paranoia levels (GHSA-89h9-2j8h-9gp2), and a multipart _charset_ shadowing trick that let attackers bypass encoding checks (GHSA-qmx4-jfcv-fgww). Beyond security, v4.30.0 adds detections for Active Directory ds tools, Velocity/FreeMarker SSTI, and SELinux commands, while repairing the response-skipping flag. Operators on any v4.x between 4.0.0 and 4.29.x should upgrade to v4.30.0 or v4.25.2 LTS, or apply the advisories' targeted workarounds.

OWASP CRS v4.30.0 and v4.25.2 LTS Ship Three Critical WAF Bypass Fixes @ Linux Compatible