Skip to content

libModSecurity3: REQUEST_HEADERS names are treated as case sensitive with configure-time rule-exclusions #3609

Description

@EsadCetiner

Describe the bug

This bug is similar to: #3441, which also doesn't appear in ModSecurity2.

Logs and dumps

N/A

To Reproduce

Re-using the previous example in this issue, say I have this rule:

SecRule REQUEST_HEADERS:Referer "@contains <evil-string>" \
    "id:2,\
    phase:1,\
    deny,\
    t:none,\
    log"

and I want to write a rule-exclusion for this rule via a configure-time rule-exclusion:

SecRuleUpdateTargetById 2 !REQUEST_HEADERS:referer

This rule-exclusion works if the client sends a lowercase referer header:

$ curl -H "referer: <evil-string>" localhost:8080

But if the client sends an uppercase referer header, then the request is wrongly blocked:

$ curl -H "Referer: <evil-string>" localhost:8080
<html>
<head><title>403 Forbidden</title></head>
<body>
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/1.28.3 (Ubuntu)</center>
</body>
</html>

If I exclude both uppercase and lowercase referer header, then the rule-exclusion works as expected.

SecRuleUpdateTargetById 2 !REQUEST_HEADERS:Referer
SecRuleUpdateTargetById 2 !REQUEST_HEADERS:referer

Expected behavior

Request header case should be ignored.

Server (please complete the following information):

  • OS: Ubuntu 26.04
  • ModSecurity Version: 3.0.17
  • NGINX Connector Version: v1.0.4
  • NGINX Version: 1.28.3

Rule Set (please complete the following information):

N/A

Additional context

Similar to: #3441

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions