Preliminary research
CVE-2026-21876: bypassing OWASP CRS by overwriting the multipart charset in a later segment
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Shows an OWASP CRS multipart rule overwriting one capture variable while iterating header values. A harmless charset in a later part hides an earlier dangerous value from final validation; the research and fix discussion illustrate why captures must be retained and checked per occurrence, including duplicate part names.
Record
- Researcher
- daytriftnewgen (some0ne)
- Published by
- Habr
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of daytriftnewgen (some0ne), first published at the original source. Preserved copies are kept so the citation survives its host.