Web Hack List

Preliminary research

CVE-2026-21876: bypassing OWASP CRS by overwriting the multipart charset in a later segment

CVE-2026-21876: Multipart Charset Validation Bypass in OWASP CRS

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Shows an OWASP CRS multipart rule overwriting one capture variable while iterating header values. A harmless charset in a later part hides an earlier dangerous value from final validation; the research and fix discussion illustrate why captures must be retained and checked per occurrence, including duplicate part names.

Record

Document
CVE-2026-21876: Multipart Charset Validation Bypass in OWASP CRS
Researcher
daytriftnewgen (some0ne)
Published by
Habr
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of daytriftnewgen (some0ne), first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .