Web Application Firewall Flaw in Coraza by OWASP
CVE-2026-107835
What is CVE-2026-107835?
The OWASP Coraza WAF, a web application firewall compatible with ModSecurity, includes a vulnerability in its cookie parsing logic prior to version 3.8.1. This flaw stems from the improper handling of boundary ASCII control characters and inconsistency in parsing empty or control-only cookie names. An unauthenticated attacker can exploit this vulnerability by crafting specially formatted Cookie headers, which may lead Coraza to index or discard cookies under different names or values than those expected by the backend application. Consequently, this can result in security rules that target REQUEST_COOKIES or REQUEST_COOKIES_NAMES failing to detect malicious activity. The potential impact and exploitation of this vulnerability depend on the specific backend parser's behavior and the configured rule scope. Users are advised to update to version 3.8.1, which addresses these issues.
Affected Version(s)
coraza < 3.8.1
