
Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.
CVE-2026-21876 docker container + minimal PoC.
I would like to thank @airween and @fzipi separately for their quick response! The vulnerability fix was ready in a very short time.
Run:
cd springboot_undertow_stand # or aspnet_stand
docker compose up --build
python3 demo/send.py # BASELINE -> 403, BYPASS -> 200 + reconstructed payload