Web Application Firewall Vulnerability in Coraza by OWASP
CVE-2025-29914
5.4MEDIUM
What is CVE-2025-29914?
The OWASP Coraza WAF is a web application firewall implemented in Golang, designed for security against various web threats. Prior to version 3.3.3, it contained a vulnerability that occurs when processing URIs that begin with double slashes (//). Instead of accurately capturing the requested filename, the firewall incorrectly sets REQUEST_FILENAME to an unintended value. For example, if the malicious URI //bar/uploads/foo.php?a=b is processed, the REQUEST_FILENAME may be improperly set to /uploads/foo.php. This misconfiguration can potentially lead to web security rule bypasses, undermining the integrity of the security protocols enforced by the WAF. The issue has been resolved in version 3.3.3.
Affected Version(s)
coraza < 3.3.3
