{"id":"CVE-2023-38199","details":"coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka \"Content-Type confusion\" between the WAF and the backend application. This occurs when the web application relies on only the last Content-Type header. Other platforms may reject the additional Content-Type header or merge conflicting headers, leading to detection as a malformed header.","modified":"2026-08-12T03:51:48.932431398Z","published":"2023-07-13T00:00:00Z","related":["openSUSE-SU-2024:13187-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38199.json","cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38199.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38199"},{"type":"REPORT","url":"https://github.com/coreruleset/coreruleset/issues/3191"},{"type":"FIX","url":"https://github.com/coreruleset/coreruleset/pull/3237"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coreruleset/coreruleset","events":[{"introduced":"0"},{"fixed":"98b9d811f34a1aa72792aaf6245cb2f2c0f0a5b8"}],"database_specific":{"cpe":"cpe:2.3:a:owasp:coreruleset:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.3.4"},{"last_affected":"3.3.4"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["v3.3.3","v3.3.2","v3.3.1-rc1","v3.3.0","v3.3.0-rc2","v3.3.0-rc1","v3.2.0-rc1","v3.2-rc1","v3.1.0-rc1","v3.0.1","v3.0.0-rc3","v3.0.0-rc2","v3.0.0-rc1","v2.2.7","v2.2.6","v2.2.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38199.json"}}],"schema_version":"1.9.0"}