Multipart File Handling Vulnerability in OWASP Coraza WAF
CVE-2026-107834

5.3MEDIUM

Key Information:

Vendor

Corazawaf

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107834?

The multipart handling feature in OWASP Coraza WAF, from versions 3.0.0 to 3.8.0, is vulnerable to file descriptor exhaustion. An unauthenticated attacker can exploit this by submitting multipart requests containing numerous minimal file parts, resulting in temporary file descriptors remaining open. This behavior can lead to failures in creating temporary files, error responses, and disruption of legitimate file uploads. The issue has been addressed in version 3.8.0.

Affected Version(s)

coraza >= 3.0.0, < 3.8.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.