Contact Us

We strive to make OWASP ModSecurity accessible to a wide audience of beginner and experienced users. We are interested in hearing any bug reports, false positive alert reports, evasions, usability issues, and suggestions for new detections.


Report an Issue

Create an issue on GitHub to report a false positive or false negative (evasion). Please include your installed version and the relevant portions of your engine audit log. We will try and address your issue and potentially ask for additional information in order to reproduce your problem. Please also note that stale issues will be flagged and closed after 120 days.

Chat with the Developers

Whether you want to ask questions, learn from others, or get involved as a contributor, you’re welcome to join the #project-modsecurity channel on the OWASP Slack.

Responsible Disclosure

If you’ve found a false negative/bypass under active exploit, please responsibly disclose the issue by sending an email to [email protected]. If necessary, you can send a message encrypted to our GPG key.