<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T05:05:46.618250+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-385200</id>
    <title>EUVD-2026-385200</title>
    <updated>2026-10-10T05:05:46.671448+00:00</updated>
    <content>EUVD-2026-385200</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-385200"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107834</id>
    <title>fkie_cve-2026-107834</title>
    <updated>2026-10-10T05:05:46.671488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-107834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rp9v-7xv3-r6g3</id>
    <title>GHSA-rp9v-7xv3-r6g3 — Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor</title>
    <updated>2026-10-10T05:05:46.671525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/corazawaf/coraza/v3</p>
<p>## Summary</p>
<p>`defer temp.Close()` sits inside a `for` loop in the multipart processor. Go defers run at function return, not loop end, so every file part in the request holds an open fd until `ProcessRequest()` exits. Send enough parts and you hit `EMFILE`. With CRS loaded, that flips `MULTIPART_STRICT_ERROR` to 1 and rule `200001` starts returning 400s, including on legitimate requests hitting the same condition.</p>
<p>## Details</p>
<p>`internal/bodyprocessors/multipart.go`, line 69:</p>
<p>```go
for {
    p, err := mr.NextPart()
    // ...
    temp, err := os.CreateTemp(storagePath, "crzmp*")
    defer temp.Close() // wrong scope
    io.Copy(temp, p)
}
```</p>
<p>Each iteration opens a temp file and defers its close. All of them stack up and fire together when `ProcessRequest` returns. 500 parts, 500 fds held simultaneously.</p>
<p>The body size limit (default 128MB) caps total bytes, not part count. A minimal file part (boundary line, `Content-Disposition` with `filename=`, one byte of content) is about 104 bytes. That's roughly 65,000 parts per 6.8MB of body, which on a standard Linux system (hard fd limit 65536) is enough to exhaust the table.</p>
<p>Fix is straightforward: call `temp.Close()` explicitly after `io.Copy` instead of deferring it.</p>
<p>## PoC</p>
<p>Tested on v3.7.0 (`db9850b`), Go 1.25, Linux x86_64.</p>
<p>Add this file at `internal/bodyprocessors/poc_fd_test.go` and run:</p>
<p>```text
go test -v -run TestMultipartFDLeak ./internal/bodyprocessors/...
```</p>
<p>```go
package bodyprocessors_test</p>
<p>import (
	"fmt"
	"o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rp9v-7xv3-r6g3"/>
  </entry>
</feed>
