Web Application Firewall Vulnerability in OWASP Coraza by Coraza WAF
CVE-2026-107825

4MEDIUM

Key Information:

Vendor

Corazawaf

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107825?

The OWASP Coraza WAF, a golang modsecurity-compatible web application firewall library, has been found to improperly handle the parsing of URLs during request processing. Versions 3.0.0 to 3.8.0 retain the raw URI string while failing to populate key query parameters, including QUERY_STRING and ARGS_GET. This flaw can be exploited by an unauthenticated attacker through crafted URIs sent via integrations like coraza-spoa, coraza-proxy-wasm, or custom FFI hosts, thus allowing the attacker to bypass security rules that target these parameters. It is important to note that the bundled coraza/v3/http integration remains secure as it rejects malformed request targets before they can reach Coraza. The issue has been addressed in version 3.8.0.

Affected Version(s)

coraza >= 3.0.0, < 3.8.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.