CVE-2019-19886

Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.
Configurations

Configuration 1 (hide)

cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

History

03 Jul 2025, 20:59

Type Values Removed Values Added
First Time Owasp
Owasp modsecurity
CPE cpe:2.3:a:trustwave:modsecurity:*:*:*:*:*:*:*:* cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:*

Information

Published : 2020-01-21 22:15

Updated : 2025-07-03 20:59


NVD link : CVE-2019-19886

Mitre link : CVE-2019-19886

CVE.ORG link : CVE-2019-19886


JSON object : View

Products Affected

fedoraproject

  • fedora

owasp

  • modsecurity
CWE
CWE-404

Improper Resource Shutdown or Release