finds.dev← search

// the find

owasp-modsecurity/ModSecurity

★ 9,792 · C++ · Apache-2.0 · updated Sep 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.

Libmodsecurity is the core C++ engine behind ModSecurity v3, a WAF that parses SecRules-format rules (including the OWASP Core Rule Set) and applies them to HTTP traffic. It's not a drop-in server module anymore — you pair it with a separate 'Connector' repo per webserver (Nginx, Apache, IIS), so it's for people building or maintaining WAF infrastructure, not app developers looking for a quick security add-on.

Ripping out the Apache dependency and splitting connectors into separate repos is a real architectural improvement — each connector gets its own release cycle instead of being coupled to libmodsecurity's. It's moved onto actively maintained dependencies (PCRE2 over legacy PCRE, libmaxminddb over the archived GeoIP C API), which matters for a security tool that otherwise bitrots quietly. The C and C++ dual API plus a benchmark harness with real OWASP CRS rule sets means you can actually measure the perf cost of your ruleset before shipping it.

It's a C++ engine parsing untrusted HTTP input on the request path — exactly the kind of attack surface where memory-safety bugs are most dangerous, and there's no mention of fuzzing in the CI setup. The submodule situation is fragile: the mbedtls v3→v4 migration restructured things enough that stale submodules silently break the build, and the README has to spend real estate walking through how to tell if you forgot `--init --recursive`. Trustwave's sponsorship ended mid-2024, which is a funding question mark for a security-critical library people put in their request path. Build tooling is still autotools-based on Unix with a bolted-on CMake path for Windows, and actually using this means standing up and version-matching a separate connector project rather than just linking one library.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →