<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T01:46:52.654003+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-385211</id>
    <title>EUVD-2026-385211</title>
    <updated>2026-10-10T01:46:52.656163+00:00</updated>
    <content>EUVD-2026-385211</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-385211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107833</id>
    <title>fkie_cve-2026-107833</title>
    <updated>2026-10-10T01:46:52.656200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-107833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3c6w-j9xm-8h2h</id>
    <title>GHSA-3c6w-j9xm-8h2h — Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion</title>
    <updated>2026-10-10T01:46:52.656233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/corazawaf/coraza/v3</p>
<p>### Summary</p>
<p>The JSON response body processor parses response bodies with no recursion
limit. `ProcessResponse` calls `readJSON(ss, ignoreJSONRecursionLimit)`, and
that constant is `-1`. The guard in `readItems` only fires on `== 0`, so
counting down from `-1` (-2, -3, ...) never reaches it. The guard is effectively
dead on the response path. The request path is fine: `ProcessRequest` passes the
configured limit (default 1024). There is no equivalent directive or default for
responses.</p>
<p>Parsing a deeply nested JSON response is CPU-bound and its cost grows
quadratically with nesting depth. A 512 KiB response (the default
`ResponseBodyLimit`) holds about 87,000 nesting levels and takes ~12 s to
process, keeping one core busy the whole time.</p>
<p>### Root cause</p>
<p>`internal/bodyprocessors/json.go`</p>
<p>```go
const ignoreJSONRecursionLimit = -1                     // line 51</p>
<p>func (js *jsonBodyProcessor) ProcessResponse(reader io.Reader, v ..., _ plugintypes.BodyProcessorOptions) error {
    ...
    data, err := readJSON(ss, ignoreJSONRecursionLimit) // line 62, passes -1
}</p>
<p>func (js *jsonBodyProcessor) ProcessRequest(...) error {
    ...
    data, err := readJSON(ss, bpo.RequestBodyRecursionLimit) // line 32, default 1024
}
```</p>
<p>The guard and the decrement:</p>
<p>```go
func readItems(json gjson.Result, objKey []byte, maxRecursion int, res map[string]string) error {
    if maxRecursion == 0 {                              // line 106
        return errors.New("max recursion reached while readin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3c6w-j9xm-8h2h"/>
  </entry>
</feed>
