-
-
Notifications
You must be signed in to change notification settings - Fork 428
Pull requests: coreruleset/coreruleset
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat: resolve common false positives with ad and tracker cookies
#4378
opened Dec 9, 2025 by
EsadCetiner
Loading…
3 of 11 tasks
chore(deps): update owasp/modsecurity-crs:apache docker digest to f2523fb in tests/docker-compose.yml
dependencies
digest
docker
release:ignore
Ignore for changelog release
#4375
opened Dec 8, 2025 by
renovate
bot
Loading…
1 task
feat(942450): add another hex + binary declaration pattern
#4374
opened Dec 7, 2025 by
touchweb-vincent
Loading…
feat(942350): added replace keyword + c-type comment evasion
#4373
opened Dec 7, 2025 by
touchweb-vincent
Loading…
fix: remove bypass-vulnerable content types from default allow lists
🏁 ready to merge
#4365
opened Nov 28, 2025 by
RedXanadu
Loading…
4 of 11 tasks
test(920180): avoid content-type evasion on nginx
release:fix
#4347
opened Nov 17, 2025 by
touchweb-vincent
Loading…
feat(933100, 933160): added t:urlDecodeUni for JSON / XML urlencoded
#4345
opened Nov 17, 2025 by
touchweb-vincent
Loading…
feat: adding new rule 920341 to avoid content-type evasion on HTTP/2
#4341
opened Nov 14, 2025 by
touchweb-vincent
Loading…
fix(933150): reduce substring false positive matches
release:fix
#4340
opened Nov 14, 2025 by
EsadCetiner
Loading…
6 of 11 tasks
fix(942410): cleaning of duplicates with 942151
#4336
opened Nov 13, 2025 by
touchweb-vincent
Loading…
docs: comment on threshold should be more alarming
#4330
opened Nov 10, 2025 by
touchweb-vincent
Loading…
feat(942500): stronger hardening to improve PL1 protection
#4328
opened Nov 9, 2025 by
touchweb-vincent
Loading…
feat(941120): all HTTP headers should be checked
#4327
opened Nov 9, 2025 by
touchweb-vincent
Loading…
feat(941110): all HTTP headers should be checked
#4326
opened Nov 8, 2025 by
touchweb-vincent
Loading…
fix(942350,942360): avoid comment bypass - this should be catch on PL1
#4325
opened Nov 7, 2025 by
touchweb-vincent
Loading…
feat: add rule 920442 on PL3 to detect more file extensions
#4324
opened Nov 7, 2025 by
touchweb-vincent
Loading…
feat: add rule 920441 on PL2 to detect more file extensions
#4323
opened Nov 7, 2025 by
touchweb-vincent
Loading…
chore: improves quant output with run details
release:ignore
Ignore for changelog release
Stale
#4318
opened Nov 3, 2025 by
M4tteoP
Loading…
fix(942431): updated regex pattern to NOT include non-ascii characters
release:ignore
Ignore for changelog release
#4307
opened Oct 23, 2025 by
azurit
Loading…
fix(931130): Isolating 2-chars sequence with high risk of false positive on high entropy input
⚠️ do not merge
Additional work or discussion is needed despite passing tests
#4304
opened Oct 22, 2025 by
touchweb-vincent
Loading…
feat: add 921500 - Nonstandard urlencode characters in path
#4302
opened Oct 22, 2025 by
touchweb-vincent
Loading…
feat: update restricted files and file extensions
release:new-detection
In this PR we introduce a new detection
#4299
opened Oct 21, 2025 by
EsadCetiner
Loading…
chore(deps): update owasp/modsecurity-crs:nginx docker digest to f7d3990 in tests/docker-compose.yml
dependencies
digest
docker
release:ignore
Ignore for changelog release
#4296
opened Oct 20, 2025 by
renovate
bot
Loading…
1 task
Previous Next
ProTip!
Updated in the last three days: updated:>2025-12-06.