Current issue state, recent activity, and per-issue timelines from the indexed issue data.
| Date | Opened | Closed | Comments | Events | Open Backlog |
|---|---|---|---|---|---|
| 2026-09-20 | 0 | 0 | 0 | 0 | 1 |
| 2026-09-19 | 0 | 0 | 0 | 0 | 2 |
| 2026-09-18 | 0 | 0 | 0 | 0 | 57 |
| 2026-09-17 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-16 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-15 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-14 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-13 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-12 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-11 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-10 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-09 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-08 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-07 | 0 | 0 | 0 | 0 | 0 |
Opened: 0
Closed: 0
Comments: 0
Events: 0
| Issue | Author | State | Labels | Comments | Reactions | Updated |
|---|---|---|---|---|---|---|
#906 Dependency Dashboard Opened 3 years ago | renovate[bot] | open - reopened | No labels | 0 | 0 | 1 day ago |
#1628 Large octet-stream request bodies are force-parsed into REQUEST_BODY/ARGS and transformed → memory blow-up (SecRequestBodyNoFilesLimit not enforced; forced URLENCODED vs RAW) Opened 3 months ago | jptosso | open | No labels | 1 | 1 | 2 days ago |
#1681 Transformation cache misses on map-backed collections Opened 1 month ago | M4tteoP | open | No labels | 1 | 0 | 6 days ago |
#1611 Coraza no longer 'best effort' parses JSON messages larger than configured SecRequestBodyLimit Opened 5 months ago | Kortekaasy | open | No labels | 2 | 2 | 12 days ago |
#1714 Implement RESPONSE_XML support Opened 17 days ago | fzipi | open | No labels | 0 | 0 | 17 days ago |
#1710 Fuzz tests #1331 failed Opened 17 days ago | github-actions[bot] | closed - completed | No labels | 1 | 0 | 17 days ago |
#1566 docs: investigate RESPONSE_CONTENT_LENGTH variable Opened 6 months ago | M4tteoP | open | documentation good first issue | 1 | 0 | 19 days ago |
#1103 Native prometheus metrics Opened 2 years ago | jptosso | open | No labels | 9 | 7 | 21 days ago |
#1700 SecRuleUpdateTargetByTag silently does nothing: targets are added to a loop copy Opened 22 days ago | fzipi | closed - completed | bug seclang | 0 | 0 | 21 days ago |
#1696 URLENCODED_ERROR is never set for the condition it documents; the decoder cannot detect it Opened 23 days ago | fzipi | open | bug seclang | 0 | 0 | 23 days ago |
#1575 Add code blocks to documentation Opened 6 months ago | fzipi | closed - completed | No labels | 1 | 1 | 23 days ago |
#1686 Concurrent audit log writer: transaction ID is unsanitized in the audit record file path Opened 27 days ago | fzipi | open | No labels | 4 | 0 | 24 days ago |
#1104 Unsupported "accuracy" Action in SecRule Configuration Opened 2 years ago | tigerwill90 | closed - completed | No labels | 5 | 0 | 24 days ago |
#1685 REQUEST_BODY is not populated when a body processor ran (XML/JSON), diverging from libmodsecurity v3 Opened 1 month ago | fzipi | open | No labels | 2 | 0 | 26 days ago |
#1687 15 MULTIPART_* variables are declared but never populated, so rules referencing them silently never match Opened 27 days ago | fzipi | open | bug seclang | 0 | 0 | 27 days ago |
#1670 normalise path and normalise path win too transformations return changed true for some cases even if the path not touched Opened 2 months ago | HackingRepo | closed - completed | No labels | 0 | 1 | 1 month ago |
#1653 jsDecode doesn't decode ES2015+ \u{...} extended Unicode escapes Opened 2 months ago | fzipi | closed - completed | bug security fix | 1 | 1 | 1 month ago |
#1675 `msg`/`logdata` macros are expanded on every rule evaluation, emitting spurious "key not found in collection" warnings Opened 2 months ago | blotus | open | No labels | 0 | 1 | 1 month ago |
#1654 cssDecode writes a single raw byte for non-ASCII hex escapes instead of the codepoint's UTF-8 encoding Opened 2 months ago | fzipi | closed - completed | bug security fix | 1 | 1 | 2 months ago |
#1656 normalisePathWin doesn't strip Windows' trailing dots/spaces or ADS suffixes Opened 2 months ago | fzipi | closed - completed | bug security fix | 1 | 0 | 2 months ago |
#1651 base64DecodeExt truncates output at base64url '-'/'_', letting attacker-controlled tokens evade rules past that point Opened 2 months ago | fzipi | closed - completed | bug security fix | 0 | 1 | 2 months ago |
#1655 compressWhitespace corrupts valid UTF-8 for common accented Latin-1-supplement characters Opened 2 months ago | fzipi | closed - completed | bug security fix | 1 | 1 | 2 months ago |
#1674 cookieParser misinterepretaion of unicode cookie values Opened 2 months ago | HackingRepo | open | No labels | 0 | 0 | 2 months ago |
#1666 Replace Comment transformation have some loopholes Opened 2 months ago | HackingRepo | open | No labels | 0 | 0 | 2 months ago |
#1671 URI Decode uni discards high bits, leading to loopholes Opened 2 months ago | HackingRepo | closed - completed | No labels | 4 | 0 | 2 months ago |