CVE Explorer
CVE-2026-33691
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This is
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"coreruleset","vendor":"coreruleset","versions":[{"status":"affected","version":"< 3.3.9"},{"status":"affected","version":">= 4.0.0-rc1, < 4.25.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-178","description":"CWE-178: Improper Handling of Case Sensitivity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/problemTypes/0/descriptions/0
Source references
10 source assertions{"url":"http://seclists.org/fulldisclosure/2026/Apr/0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/adp/0/references/1
{"url":"http://www.openwall.com/lists/oss-security/2026/03/29/2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/adp/0/references/0
{"url":"http://www.openwall.com/lists/oss-security/2026/04/18/4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/adp/0/references/2
{"name":"https://github.com/coreruleset/coreruleset/commit/2a8c63512811c5dd74472becebb79a783e68ff02","tags":["x_refsource_MISC"],"url":"https://github.com/coreruleset/coreruleset/commit/2a8c63512811c5dd74472becebb79a783e68ff02"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/4
{"name":"https://github.com/coreruleset/coreruleset/pull/4546","tags":["x_refsource_MISC"],"url":"https://github.com/coreruleset/coreruleset/pull/4546"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/1
{"name":"https://github.com/coreruleset/coreruleset/pull/4547","tags":["x_refsource_MISC"],"url":"https://github.com/coreruleset/coreruleset/pull/4547"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/2
{"name":"https://github.com/coreruleset/coreruleset/pull/4548","tags":["x_refsource_MISC"],"url":"https://github.com/coreruleset/coreruleset/pull/4548"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/3
{"name":"https://github.com/coreruleset/coreruleset/releases/tag/v3.3.9","tags":["x_refsource_MISC"],"url":"https://github.com/coreruleset/coreruleset/releases/tag/v3.3.9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/5
{"name":"https://github.com/coreruleset/coreruleset/releases/tag/v4.25.0","tags":["x_refsource_MISC"],"url":"https://github.com/coreruleset/coreruleset/releases/tag/v4.25.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/6
{"name":"https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d63afd9cc93158ada006648cb4484a637dc9385d893e48897757a81845ea948a · sha256:d04b7e9c20dd9712… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.