It was discovered that one of the rules in the OWASP ModSecurity Core Rule Set parsed some multipart requests incorrectly. For the oldstable distribution (bookworm), this problem has been fixed in version 3.3.4-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in

Source: Debian: modsecurity-crs Critical Fix for CVE-2026-21876 DSA-6105-1