<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:31:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07889</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07889</link>
      <description>bdu:2026-07889</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07889</guid>
    </item>
    <item>
      <title>EUVD-2026-223973</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-223973</link>
      <description>EUVD-2026-223973</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-223973</guid>
    </item>
    <item>
      <title>fkie_cve-2025-29914</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-29914</link>
      <description>&lt;p&gt;OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-29914</guid>
    </item>
    <item>
      <title>GHSA-q9f5-625g-xm39 — OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q9f5-625g-xm39</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jptosso/coraza-waf, Go: github.com/corazawaf/coraza/v3&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;URLs starting with `//` are not parsed properly, and the request `REQUEST_FILENAME` variable contains a wrong value, leading to potential rules bypass.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If a request is made on an URI starting with `//`, coraza will set a wrong value in `REQUEST_FILENAME`.
For example, if the URI `//bar/uploads/foo.php?a=b` is passed to coraza: , `REQUEST_FILENAME` will be set to `/uploads/foo.php`.&lt;/p&gt;
&lt;p&gt;The root cause is the usage of `url.Parse` to parse the URI in [ProcessURI](https://github.com/corazawaf/coraza/blob/8b612f4e6e18c606e371110227bc7669dc714cab/internal/corazawaf/transaction.go#L768).&lt;/p&gt;
&lt;p&gt;`url.Parse` can parse both absolute URLs (starting with a scheme) or relative ones (just the path). 
`//bar/uploads/foo.php` is a valid absolute URI (the scheme is empty), `url.Parse` will consider `bar` as the host and the path will be set to `/uploads/foo.php`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/url&amp;#34;
	&amp;#34;os&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/corazawaf/coraza/v3&amp;#34;
)&lt;/p&gt;
&lt;p&gt;const testRule = `
SecDebugLogLevel 9
SecDebugLog /dev/stdout
SecRule REQUEST_FILENAME &amp;#34;@rx /bar/uploads/.*\.(h?ph(p|tm?l?|ar)|module|shtml)&amp;#34; &amp;#34;id:1,phase:1,deny&amp;#34;
`&lt;/p&gt;
&lt;p&gt;func main() {
	var testURL = &amp;#34;//bar/uploads/foo.php&amp;#34;&lt;/p&gt;
&lt;p&gt;if os.Getenv(&amp;#34;TEST_URL&amp;#34;) != &amp;#34;&amp;#34; {
		testURL = os.Getenv(&amp;#34;TEST_URL&amp;#34;)
	}&lt;/p&gt;
&lt;p&gt;fmt.Printf(&amp;#34;Testing URL: %s\n&amp;#34;, testURL)&lt;/p&gt;
&lt;p&gt;config := coraza.NewWAFConfig().WithDirectives(testRule)&lt;/p&gt;
&lt;p&gt;waf, err := coraza.NewWAF(config)&lt;/p&gt;
&lt;p&gt;if err != nil {
		panic(err)
	}&lt;/p&gt;
&lt;p&gt;tx := waf.NewTransaction()&lt;/p&gt;
&lt;p&gt;tx.ProcessURI(testURL, &amp;#34;GET&amp;#34;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jptosso/coraza-waf, Go: github.com/corazawaf/coraza/v3&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;URLs starting with `//` are not parsed properly, and the request `REQUEST_FILENAME` variable contains a wrong value, leading to potential rules bypass.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If a request is made on an URI starting with `//`, coraza will set a wrong value in `REQUEST_FILENAME`.
For example, if the URI `//bar/uploads/foo.php?a=b` is passed to coraza: , `REQUEST_FILENAME` will be set to `/uploads/foo.php`.&lt;/p&gt;
&lt;p&gt;The root cause is the usage of `url.Parse` to parse the URI in [ProcessURI](https://github.com/corazawaf/coraza/blob/8b612f4e6e18c606e371110227bc7669dc714cab/internal/corazawaf/transaction.go#L768).&lt;/p&gt;
&lt;p&gt;`url.Parse` can parse both absolute URLs (starting with a scheme) or relative ones (just the path). 
`//bar/uploads/foo.php` is a valid absolute URI (the scheme is empty), `url.Parse` will consider `bar` as the host and the path will be set to `/uploads/foo.php`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/url&amp;#34;
	&amp;#34;os&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/corazawaf/coraza/v3&amp;#34;
)&lt;/p&gt;
&lt;p&gt;const testRule = `
SecDebugLogLevel 9
SecDebugLog /dev/stdout
SecRule REQUEST_FILENAME &amp;#34;@rx /bar/uploads/.*\.(h?ph(p|tm?l?|ar)|module|shtml)&amp;#34; &amp;#34;id:1,phase:1,deny&amp;#34;
`&lt;/p&gt;
&lt;p&gt;func main() {
	var testURL = &amp;#34;//bar/uploads/foo.php&amp;#34;&lt;/p&gt;
&lt;p&gt;if os.Getenv(&amp;#34;TEST_URL&amp;#34;) != &amp;#34;&amp;#34; {
		testURL = os.Getenv(&amp;#34;TEST_URL&amp;#34;)
	}&lt;/p&gt;
&lt;p&gt;fmt.Printf(&amp;#34;Testing URL: %s\n&amp;#34;, testURL)&lt;/p&gt;
&lt;p&gt;config := coraza.NewWAFConfig().WithDirectives(testRule)&lt;/p&gt;
&lt;p&gt;waf, err := coraza.NewWAF(config)&lt;/p&gt;
&lt;p&gt;if err != nil {
		panic(err)
	}&lt;/p&gt;
&lt;p&gt;tx := waf.NewTransaction()&lt;/p&gt;
&lt;p&gt;tx.ProcessURI(testURL, &amp;#34;GET&amp;#34;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q9f5-625g-xm39</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14937-1 — govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</guid>
    </item>
  </channel>
</rss>
