Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Potential regex compilation failure or mismatch with variable-length lookbehind in PCRE patterns

Abierto
#3,537 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
48/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Tranquilo
Stack tecnológico
cpp
Área
security

Línea de trabajo

Comienza reproduciendo el ejemplo de SecRule y luego inspecciona src/utils/regex.cc, centrándote en cómo ModSecurity encapsula la compilación y la coincidencia de PCRE y PCRE2. Compara el comportamiento con lookbehind de longitud variable no compatible y con configuraciones compatibles; se considera terminado cuando el patrón coincide si es compatible o produce un error de compilación claro cuando no lo es.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

3.x

Summary
I am experiencing issues when using regular expressions containing variable-length lookbehind assertions (e.g., (?<!.(?:target|origin).{0,20})\bhaving\b) in ModSecurity v3. The pattern fails to match as expected, likely due to limitations in the underlying PCRE library integration or configuration within src/utils/regex.cc.

Steps to Reproduce
Create a SecRule using a variable-length lookbehind:

SecRule ARGS "@rx (?<!.(?:target|origin).{0,20})\bhaving\b" "id:12345,phase:2,deny,status:403"
Send a request with a payload that should match (e.g., ?data=select having count).

Observe that the rule is not triggered.

Actual Behavior
The regex fails to match the input. In some environments, no explicit compilation error is shown in the debug log, leading to "silent failure" where the rule is simply ignored.

Expected Behavior
The regex should either:

Match the input if the linked PCRE library (PCRE2 10.30+) supports variable-length lookbehind.

Provide a clear compilation error in the ModSecurity log indicating that the pattern is unsupported by the current PCRE version.

Technical Context
Looking at src/utils/regex.cc, ModSecurity wraps PCRE/PCRE2. However:

Most PCRE1 versions (still common in many distros) strictly forbid non-fixed-width lookbehind (errors like lookbehind assertion is not fixed length).

If ModSecurity is compiled with PCRE2, it should theoretically support this, but the implementation may not be passing the necessary JIT or match options to handle complex lookbehind depth.

Lenguaje dominante
C++
Estrellas
9.8k
Forks
1.8k
Merge medio
2 h 46 min
PR fusionados (30 d)
1

Preparar el entorno

  • Sin Dockerfile ni archivo de Docker Compose
  • Tiene una plantilla de pull request
  • Sin guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de owasp-modsecurity/ModSecurity

Todos los issues de owasp-modsecurity/ModSecurity

Issues similares

Más issues de C++

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.