OWASP ModSecurity

ModSecurity is the standard open-source web application firewall (WAF) engine. Originally designed as a module for the Apache HTTP Server, it has evolved to provide HTTP request and response filtering capabilities across a number of different platforms including Apache HTTP Server, Microsoft IIS and Nginx. It is free software released under the Apache license 2.0 and remains the most widespread open source web application firewall engine used by businesses, government organizations, internet service providers and commercial WAF vendors alike.

The OWASP ModSecurity project provides the WAF engine. The engine is usually coupled with OWASP CRS, the dominant WAF rule set, that brings protection against HTTP attacks.

About OWASP ModSecurity

Project Leaders

Ervin Hegedus

Email

Christian Folini

Email

Marc Stern@owasp.org

Email

Project Information

Production Project
Classification
WAF
Language
C++
License
Apache License 2.0
Latest Version
3.0.16
Contributors
143
GitHub Stars
9789
Downloads
847770
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP ModSecurity | OWASP Foundation