Potential regex compilation failure or mismatch with variable-length lookbehind in PCRE patterns
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 48/100
Línea de trabajo
Comienza reproduciendo el ejemplo de SecRule y luego inspecciona src/utils/regex.cc, centrándote en cómo ModSecurity encapsula la compilación y la coincidencia de PCRE y PCRE2. Compara el comportamiento con lookbehind de longitud variable no compatible y con configuraciones compatibles; se considera terminado cuando el patrón coincide si es compatible o produce un error de compilación claro cuando no lo es.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
I am experiencing issues when using regular expressions containing variable-length lookbehind assertions (e.g., (?<!.(?:target|origin).{0,20})\bhaving\b) in ModSecurity v3. The pattern fails to match as expected, likely due to limitations in the underlying PCRE library integration or configuration within src/utils/regex.cc.
Steps to Reproduce
Create a SecRule using a variable-length lookbehind:
SecRule ARGS "@rx (?<!.(?:target|origin).{0,20})\bhaving\b" "id:12345,phase:2,deny,status:403"
Send a request with a payload that should match (e.g., ?data=select having count).
Observe that the rule is not triggered.
Actual Behavior
The regex fails to match the input. In some environments, no explicit compilation error is shown in the debug log, leading to "silent failure" where the rule is simply ignored.
Expected Behavior
The regex should either:
Match the input if the linked PCRE library (PCRE2 10.30+) supports variable-length lookbehind.
Provide a clear compilation error in the ModSecurity log indicating that the pattern is unsupported by the current PCRE version.
Technical Context
Looking at src/utils/regex.cc, ModSecurity wraps PCRE/PCRE2. However:
Most PCRE1 versions (still common in many distros) strictly forbid non-fixed-width lookbehind (errors like lookbehind assertion is not fixed length).
If ModSecurity is compiled with PCRE2, it should theoretically support this, but the implementation may not be passing the necessary JIT or match options to handle complex lookbehind depth.
- Lenguaje dominante
- C++
- Estrellas
- 9.8k
- Forks
- 1.8k
- Merge medio
- 2 h 46 min
- PR fusionados (30 d)
- 1
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de owasp-modsecurity/ModSecurity
-
2.x Platform - IIS
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
owasp-modsecurity/ModSecurity#3623 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
owasp-modsecurity/ModSecurity#3621 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
owasp-modsecurity/ModSecurity#3619 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
owasp-modsecurity/ModSecurity#3612 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
3.x
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
owasp-modsecurity/ModSecurity#3580 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de owasp-modsecurity/ModSecurity
Issues similares
-
Dificultad 2/5 Medio día Aptitud para principiantes 84/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 88/100
ROCm/rocm-libraries#12703 ·
Los mantenedores suelen responder en 2 días
-
bug
Dificultad 1/5 1-3 horas Aptitud para principiantes 88/100
isl-org/Open3D#7585 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
Feature request
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
qbittorrent/qBittorrent#24975 ·
Los mantenedores suelen responder en 3 días