<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:24:48.643240+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07889</id>
    <title>bdu:2026-07889</title>
    <updated>2026-10-04T06:24:48.720997+00:00</updated>
    <content>bdu:2026-07889</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-223973</id>
    <title>EUVD-2026-223973</title>
    <updated>2026-10-04T06:24:48.721034+00:00</updated>
    <content>EUVD-2026-223973</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-223973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-29914</id>
    <title>fkie_cve-2025-29914</title>
    <updated>2026-10-04T06:24:48.721049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-29914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q9f5-625g-xm39</id>
    <title>GHSA-q9f5-625g-xm39 — OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`</title>
    <updated>2026-10-04T06:24:48.721080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/jptosso/coraza-waf, Go: github.com/corazawaf/coraza/v3</p>
<p>### Summary</p>
<p>URLs starting with `//` are not parsed properly, and the request `REQUEST_FILENAME` variable contains a wrong value, leading to potential rules bypass.</p>
<p>### Details</p>
<p>If a request is made on an URI starting with `//`, coraza will set a wrong value in `REQUEST_FILENAME`.
For example, if the URI `//bar/uploads/foo.php?a=b` is passed to coraza: , `REQUEST_FILENAME` will be set to `/uploads/foo.php`.</p>
<p>The root cause is the usage of `url.Parse` to parse the URI in [ProcessURI](https://github.com/corazawaf/coraza/blob/8b612f4e6e18c606e371110227bc7669dc714cab/internal/corazawaf/transaction.go#L768).</p>
<p>`url.Parse` can parse both absolute URLs (starting with a scheme) or relative ones (just the path). 
`//bar/uploads/foo.php` is a valid absolute URI (the scheme is empty), `url.Parse` will consider `bar` as the host and the path will be set to `/uploads/foo.php`.</p>
<p>### PoC</p>
<p>```go
package main</p>
<p>import (
	"fmt"
	"net/url"
	"os"</p>
<p>"github.com/corazawaf/coraza/v3"
)</p>
<p>const testRule = `
SecDebugLogLevel 9
SecDebugLog /dev/stdout
SecRule REQUEST_FILENAME "@rx /bar/uploads/.*\.(h?ph(p|tm?l?|ar)|module|shtml)" "id:1,phase:1,deny"
`</p>
<p>func main() {
	var testURL = "//bar/uploads/foo.php"</p>
<p>if os.Getenv("TEST_URL") != "" {
		testURL = os.Getenv("TEST_URL")
	}</p>
<p>fmt.Printf("Testing URL: %s\n", testURL)</p>
<p>config := coraza.NewWAFConfig().WithDirectives(testRule)</p>
<p>waf, err := coraza.NewWAF(config)</p>
<p>if err != nil {
		panic(err)
	}</p>
<p>tx := waf.NewTransaction()</p>
<p>tx.ProcessURI(testURL, "GET"…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q9f5-625g-xm39"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</id>
    <title>openSUSE-SU-2025:14937-1 — govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media</title>
    <updated>2026-10-04T06:24:48.721137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1"/>
  </entry>
</feed>
