Repository navigation
Security: corazawaf/coraza
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)GHSA-6gcq-wc29-5xf2 published
Oct 2, 2026 by fzipiHigh -
Unbounded recursion in JSON response body processor causes CPU exhaustionGHSA-3c6w-j9xm-8h2h published
Oct 2, 2026 by fzipiModerate -
Resource exhaustion via deferred file handle accumulation in multipart body processorGHSA-rp9v-7xv3-r6g3 published
Oct 2, 2026 by fzipiModerate -
JSON key collision in Coraza body processor allows unauthenticated attackers to bypass OWASP CRS inspectionGHSA-5gj4-9gm7-2fx2 published
Oct 2, 2026 by fzipiModerate -
URL-encoded form Content-Type parameters bypass Coraza body inspectionGHSA-w253-m66g-rx24 published
Oct 2, 2026 by fzipiModerate -
Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rulesGHSA-3wr7-993q-jrff published
Oct 2, 2026 by fzipiModerate -
Cookie Parser ConfusionGHSA-g4qm-m288-5cp9 published
Oct 2, 2026 by fzipiModerate -
jsDecode Off-by-One in Octal Escape Handling Enables WAF BypassGHSA-pc5q-qfxp-ggqv published
Oct 2, 2026 by fzipiModerate -
ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrationsGHSA-x26q-wvhg-fh4m published
Oct 2, 2026 by fzipiModerate -
Native audit-log format allows CRLF injection and log forgery via request body and header fieldsGHSA-prpw-wwv7-xjjr published
Oct 2, 2026 by fzipiModerate