Search
Find a vulnerability
Search criteria
14 vulnerabilities by corazawaf
CVE-2026-107835 (GCVE-0-2026-107835)
Vulnerability from nvd – Published: 2026-10-09 17:46 – Updated: 2026-10-09 18:24
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: Cookie Parser Confusion
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.
Severity
4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 18:23 UTC
CWE
- CWE-436 - Interpretation Conflict
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/0b940e… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/commit/9f8521… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-107835",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T18:23:53.273353Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T18:24:00.100Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003c 3.8.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory\u0027s remediation. This issue is fixed in version 3.8.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-436",
"description": "CWE-436: Interpretation Conflict",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:46:58.890Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9"
},
{
"name": "https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af"
},
{
"name": "https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1"
}
],
"source": {
"advisory": "GHSA-g4qm-m288-5cp9",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: Cookie Parser Confusion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107835",
"datePublished": "2026-10-09T17:46:58.890Z",
"dateReserved": "2026-10-08T22:34:49.289Z",
"dateUpdated": "2026-10-09T18:24:00.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107834 (GCVE-0-2026-107834)
Vulnerability from nvd – Published: 2026-10-09 17:41 – Updated: 2026-10-09 17:41
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.
Severity
5.3 (Medium)
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/1bc390… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.0 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-772",
"description": "CWE-772: Missing Release of Resource after Effective Lifetime",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:41:07.802Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3"
},
{
"name": "https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
}
],
"source": {
"advisory": "GHSA-rp9v-7xv3-r6g3",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107834",
"datePublished": "2026-10-09T17:41:07.802Z",
"dateReserved": "2026-10-08T22:34:49.289Z",
"dateUpdated": "2026-10-09T17:41:07.802Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107833 (GCVE-0-2026-107833)
Vulnerability from nvd – Published: 2026-10-09 17:39 – Updated: 2026-10-09 18:02
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.
Severity
5.9 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 18:01 UTC
CWE
- CWE-674 - Uncontrolled Recursion
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/cae3c7… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-107833",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T18:01:32.504807Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T18:02:08.775Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:39:48.049Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h"
},
{
"name": "https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
}
],
"source": {
"advisory": "GHSA-3c6w-j9xm-8h2h",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107833",
"datePublished": "2026-10-09T17:39:48.049Z",
"dateReserved": "2026-10-08T22:34:49.288Z",
"dateUpdated": "2026-10-09T18:02:08.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107826 (GCVE-0-2026-107826)
Vulnerability from nvd – Published: 2026-10-09 17:33 – Updated: 2026-10-09 17:55
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1.
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 17:55 UTC
CWE
- CWE-674 - Uncontrolled Recursion
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/814e18… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-107826",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T17:55:09.069803Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:55:14.751Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:33:49.389Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2"
},
{
"name": "https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1"
}
],
"source": {
"advisory": "GHSA-6gcq-wc29-5xf2",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107826",
"datePublished": "2026-10-09T17:33:49.389Z",
"dateReserved": "2026-10-08T21:23:59.824Z",
"dateUpdated": "2026-10-09T17:55:14.751Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107825 (GCVE-0-2026-107825)
Vulnerability from nvd – Published: 2026-10-09 17:32 – Updated: 2026-10-09 17:32
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.
Severity
4 (Medium)
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/0321af… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.0 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20: Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-436",
"description": "CWE-436: Interpretation Conflict",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:32:11.506Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m"
},
{
"name": "https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
}
],
"source": {
"advisory": "GHSA-x26q-wvhg-fh4m",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure \u2014 defense-in-depth bypass for non-net/http integrations"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107825",
"datePublished": "2026-10-09T17:32:11.506Z",
"dateReserved": "2026-10-08T21:23:59.824Z",
"dateUpdated": "2026-10-09T17:32:11.506Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-29914 (GCVE-0-2025-29914)
Vulnerability from nvd – Published: 2025-03-20 17:44 – Updated: 2025-03-20 18:18
VLAI
EPSS
VEX
Title
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-03-20 18:18 UTC
CWE
- CWE-706 - Use of Incorrectly-Resolved Name or Reference
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/4722c9… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-29914",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-20T18:18:13.186973Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-20T18:18:27.514Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003c 3.3.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-706",
"description": "CWE-706: Use of Incorrectly-Resolved Name or Reference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-20T17:44:59.024Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-q9f5-625g-xm39",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-q9f5-625g-xm39"
},
{
"name": "https://github.com/corazawaf/coraza/commit/4722c9ad0d502abd56b8d6733c6b47eb4111742d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/4722c9ad0d502abd56b8d6733c6b47eb4111742d"
}
],
"source": {
"advisory": "GHSA-q9f5-625g-xm39",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2025-29914",
"datePublished": "2025-03-20T17:44:59.024Z",
"dateReserved": "2025-03-12T13:42:22.135Z",
"dateUpdated": "2025-03-20T18:18:27.514Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-40586 (GCVE-0-2023-40586)
Vulnerability from nvd – Published: 2023-08-25 20:35 – Updated: 2024-10-02 14:41
VLAI
EPSS
VEX
Title
go package github.com/corazawaf/coraza is vulnerable to denial of service
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-10-02 14:38 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/a5239b… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T18:38:50.961Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h",
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h"
},
{
"name": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-40586",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-02T14:38:08.187080Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-10-02T14:41:35.285Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003c 3.0.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.\n"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-08-25T20:35:27.459Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h"
},
{
"name": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c"
}
],
"source": {
"advisory": "GHSA-c2pj-v37r-2p6h",
"discovery": "UNKNOWN"
},
"title": "go package github.com/corazawaf/coraza is vulnerable to denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2023-40586",
"datePublished": "2023-08-25T20:35:27.459Z",
"dateReserved": "2023-08-16T18:24:02.392Z",
"dateUpdated": "2024-10-02T14:41:35.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2026-107835 (GCVE-0-2026-107835)
Vulnerability from cvelistv5 – Published: 2026-10-09 17:46 – Updated: 2026-10-09 18:24
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: Cookie Parser Confusion
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.
Severity
4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 18:23 UTC
CWE
- CWE-436 - Interpretation Conflict
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/0b940e… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/commit/9f8521… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-107835",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T18:23:53.273353Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T18:24:00.100Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003c 3.8.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory\u0027s remediation. This issue is fixed in version 3.8.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-436",
"description": "CWE-436: Interpretation Conflict",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:46:58.890Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9"
},
{
"name": "https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af"
},
{
"name": "https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1"
}
],
"source": {
"advisory": "GHSA-g4qm-m288-5cp9",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: Cookie Parser Confusion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107835",
"datePublished": "2026-10-09T17:46:58.890Z",
"dateReserved": "2026-10-08T22:34:49.289Z",
"dateUpdated": "2026-10-09T18:24:00.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107834 (GCVE-0-2026-107834)
Vulnerability from cvelistv5 – Published: 2026-10-09 17:41 – Updated: 2026-10-09 17:41
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.
Severity
5.3 (Medium)
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/1bc390… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.0 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-772",
"description": "CWE-772: Missing Release of Resource after Effective Lifetime",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:41:07.802Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3"
},
{
"name": "https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
}
],
"source": {
"advisory": "GHSA-rp9v-7xv3-r6g3",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107834",
"datePublished": "2026-10-09T17:41:07.802Z",
"dateReserved": "2026-10-08T22:34:49.289Z",
"dateUpdated": "2026-10-09T17:41:07.802Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107833 (GCVE-0-2026-107833)
Vulnerability from cvelistv5 – Published: 2026-10-09 17:39 – Updated: 2026-10-09 18:02
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.
Severity
5.9 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 18:01 UTC
CWE
- CWE-674 - Uncontrolled Recursion
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/cae3c7… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-107833",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T18:01:32.504807Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T18:02:08.775Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:39:48.049Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h"
},
{
"name": "https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
}
],
"source": {
"advisory": "GHSA-3c6w-j9xm-8h2h",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107833",
"datePublished": "2026-10-09T17:39:48.049Z",
"dateReserved": "2026-10-08T22:34:49.288Z",
"dateUpdated": "2026-10-09T18:02:08.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107826 (GCVE-0-2026-107826)
Vulnerability from cvelistv5 – Published: 2026-10-09 17:33 – Updated: 2026-10-09 17:55
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1.
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 17:55 UTC
CWE
- CWE-674 - Uncontrolled Recursion
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/814e18… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-107826",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T17:55:09.069803Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:55:14.751Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:33:49.389Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2"
},
{
"name": "https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.1"
}
],
"source": {
"advisory": "GHSA-6gcq-wc29-5xf2",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107826",
"datePublished": "2026-10-09T17:33:49.389Z",
"dateReserved": "2026-10-08T21:23:59.824Z",
"dateUpdated": "2026-10-09T17:55:14.751Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-107825 (GCVE-0-2026-107825)
Vulnerability from cvelistv5 – Published: 2026-10-09 17:32 – Updated: 2026-10-09 17:32
VLAI
EPSS
VEX
Title
OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.
Severity
4 (Medium)
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/0321af… | x_refsource_MISC |
| https://github.com/corazawaf/coraza/releases/tag/v3.8.0 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.8.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20: Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-436",
"description": "CWE-436: Interpretation Conflict",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T17:32:11.506Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m"
},
{
"name": "https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa"
},
{
"name": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
}
],
"source": {
"advisory": "GHSA-x26q-wvhg-fh4m",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure \u2014 defense-in-depth bypass for non-net/http integrations"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-107825",
"datePublished": "2026-10-09T17:32:11.506Z",
"dateReserved": "2026-10-08T21:23:59.824Z",
"dateUpdated": "2026-10-09T17:32:11.506Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-29914 (GCVE-0-2025-29914)
Vulnerability from cvelistv5 – Published: 2025-03-20 17:44 – Updated: 2025-03-20 18:18
VLAI
EPSS
VEX
Title
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-03-20 18:18 UTC
CWE
- CWE-706 - Use of Incorrectly-Resolved Name or Reference
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/4722c9… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-29914",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-20T18:18:13.186973Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-20T18:18:27.514Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003c 3.3.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-706",
"description": "CWE-706: Use of Incorrectly-Resolved Name or Reference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-20T17:44:59.024Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-q9f5-625g-xm39",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-q9f5-625g-xm39"
},
{
"name": "https://github.com/corazawaf/coraza/commit/4722c9ad0d502abd56b8d6733c6b47eb4111742d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/4722c9ad0d502abd56b8d6733c6b47eb4111742d"
}
],
"source": {
"advisory": "GHSA-q9f5-625g-xm39",
"discovery": "UNKNOWN"
},
"title": "OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2025-29914",
"datePublished": "2025-03-20T17:44:59.024Z",
"dateReserved": "2025-03-12T13:42:22.135Z",
"dateUpdated": "2025-03-20T18:18:27.514Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-40586 (GCVE-0-2023-40586)
Vulnerability from cvelistv5 – Published: 2023-08-25 20:35 – Updated: 2024-10-02 14:41
VLAI
EPSS
VEX
Title
go package github.com/corazawaf/coraza is vulnerable to denial of service
Summary
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-10-02 14:38 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/corazawaf/coraza/security/advi… | x_refsource_CONFIRM |
| https://github.com/corazawaf/coraza/commit/a5239b… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T18:38:50.961Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h",
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h"
},
{
"name": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-40586",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-02T14:38:08.187080Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-10-02T14:41:35.285Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "coraza",
"vendor": "corazawaf",
"versions": [
{
"status": "affected",
"version": "\u003c 3.0.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.\n"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-08-25T20:35:27.459Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h"
},
{
"name": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c"
}
],
"source": {
"advisory": "GHSA-c2pj-v37r-2p6h",
"discovery": "UNKNOWN"
},
"title": "go package github.com/corazawaf/coraza is vulnerable to denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2023-40586",
"datePublished": "2023-08-25T20:35:27.459Z",
"dateReserved": "2023-08-16T18:24:02.392Z",
"dateUpdated": "2024-10-02T14:41:35.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}