Preliminary research
CVE-2026-21876: bypassing OWASP CRS by overwriting the multipart charset in a later segment
CVE-2026-21876: Multipart Charset Validation Bypass in OWASP CRS
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Shows an OWASP CRS multipart rule overwriting one capture variable while iterating header values. A harmless charset in a later part hides an earlier dangerous value from final validation; the research and fix discussion illustrate why captures must be retained and checked per occurrence, including duplicate part names.
Record
- Document
- CVE-2026-21876: Multipart Charset Validation Bypass in OWASP CRS
- Researcher
- daytriftnewgen (some0ne)
- Published by
- Habr
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of daytriftnewgen (some0ne), first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .