Web Application Firewall Vulnerability in Coraza by OWASP
CVE-2025-29914

5.4MEDIUM

Key Information:

Vendor

Corazawaf

Status
Vendor
CVE Published:
20 March 2025

What is CVE-2025-29914?

The OWASP Coraza WAF is a web application firewall implemented in Golang, designed for security against various web threats. Prior to version 3.3.3, it contained a vulnerability that occurs when processing URIs that begin with double slashes (//). Instead of accurately capturing the requested filename, the firewall incorrectly sets REQUEST_FILENAME to an unintended value. For example, if the malicious URI //bar/uploads/foo.php?a=b is processed, the REQUEST_FILENAME may be improperly set to /uploads/foo.php. This misconfiguration can potentially lead to web security rule bypasses, undermining the integrity of the security protocols enforced by the WAF. The issue has been resolved in version 3.3.3.

Affected Version(s)

coraza < 3.3.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.