OWASP CRS v4.25.0 LTS is out! First Long-Term Support for CRS 4 — stable foundation with security patches through Q3 2027. Formal backport policy, lessons from 3.3 applied, and crslang on the horizon.
https://t.co/kwTdZapXw5
Part 2 of the CRS 3→4 migration series: configuration. Don't reuse your old crs-setup.conf — variables were renamed, split, and added. Post includes a full checklist and an interactive migration tool.
https://t.co/dbxfKx98AU
#OWASP#CRS#WAF#AppSec
Migrating from OWASP CRS 3.3 to 4.25 LTS? Part 1 of a 7-part series is out — covering what changed, what breaks, and how to plan your upgrade. ~500 changes, new plugin architecture, RE2/Hyperscan compat, and more.
https://t.co/wuWbUduy2j
🔒 Security Advisory: OWASP CRS file upload extension checks could be bypassed using whitespace padding in filenames (e.g. shell. php). CVE-2026-33691, Moderate severity.
Upgrade to CRS v4.25.0 or v3.3.9.
Thanks @HackingRepo for the report!
https://t.co/pNvmSC4VDr
📢 Open WAF Day 2026 — Vienna, June 24th! 🇦🇹
A free, full-day event on WAFs, @coreruleset, and open-source security. CFP is open!
🎟️ Register: https://t.co/51hatpr5tl
🎤 Submit a talk: https://t.co/3mVI9aBava
See you there! 🚀
#OWASP#WAF#AppSec#CRS
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out 👉 https://t.co/Z8n1No7eKc
#WAF#AppSec#OWASP#ModSecurity
🎉 Introducing seclang_parser - a unified ANTLR-based parser for SecLang! One grammar, multiple languages (Go & Python), endless possibilities for WAF tooling: linters, IDE integration, config management & more.
🔗 https://t.co/C59bfOaRAM
CRS3→CRS4 migration made easy! 🚀
🧩 New GPL plugin lets you:
• Run CRS4 in monitor mode over CRS3
• Weed out false positives
• Gradually enable blocking or sampling
https://t.co/7UdYMqzN1X
#OWASP#CRS#Security
CRS will have its second community call on September 22, from 20:30 to 21:30 CEST (18:30 UTC / 2:30 p.m. ET) and will be moderated by former CRS co-leader Christian Folini. Check more details and register here: https://t.co/uN4E3Z2jZt
A critical vulnerability in Microsoft Sharepoint was recently discovered, allowing remote code execution -- in many cases, leading to persistence for the attackers, exfiltration of data, and more. Users of CRS were already covered from day zero using PL2.
CRS will have its first community call on March 17, from 20:30 to 21:30 CET (19:30 UTC / 2:30 p.m. ET) and will be moderated by former CRS co-leader Christian Folini. Register here: https://t.co/Ib7AXFzipX
A somewhat diminished OWASP CRS core team at the annual developers retreat / the @owasp project summit 2024 in Woburn Forest (group photo without squirrels and deer).
Meet the CRS team: Whether it's work or hobbies, Max – the Kiwi-German software developer from the Swiss Alps – wants to enjoy what he does. For him, the most important thing about the CRS project is the people. Read his portrait: https://t.co/OWoDltZgMm
We are excited to announce United Security Providers as Gold Sponsor of @CoreRuleSet. USP has been using CRS for a long time as an important component of its web access management solution. Support from sponsors is of great importance for the CRS project. https://t.co/qOzzQvw4t3
Thank you, United Security Providers, for supporting the @CoreRuleSet as new GOLD sponsor! The specialist for application and network security has been using CRS for a long time. Support from sponsors like @uspag is of great importance for open-source projects like CRS.
#crs#WAF
Wir sind stolz darauf, als Goldsponsor das OWASP CRS-Projekt zu unterstützen! 🚀
Unsere Entwickler tragen aktiv zur Weiterentwicklung bei und stärken die Open-Source-Community.
Hier geht's zur Pressemitteilung: https://t.co/RWZ1dja2gj
#CyberSecurity#OWASP#CRS#OpenSource
The CRS project has released version 4.6.0 for CRS 4 and version 3.3.6 for CRS 3.
The new releases tackle two multipart file upload bypass methods. All users are requested to update to the new releases.
Read more and get the new releases: https://t.co/mnwxjirzWw