Web Application Firewall Flaw in Coraza by OWASP
CVE-2026-107835

4MEDIUM

Key Information:

Vendor

Corazawaf

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107835?

The OWASP Coraza WAF, a web application firewall compatible with ModSecurity, includes a vulnerability in its cookie parsing logic prior to version 3.8.1. This flaw stems from the improper handling of boundary ASCII control characters and inconsistency in parsing empty or control-only cookie names. An unauthenticated attacker can exploit this vulnerability by crafting specially formatted Cookie headers, which may lead Coraza to index or discard cookies under different names or values than those expected by the backend application. Consequently, this can result in security rules that target REQUEST_COOKIES or REQUEST_COOKIES_NAMES failing to detect malicious activity. The potential impact and exploitation of this vulnerability depend on the specific backend parser's behavior and the configured rule scope. Users are advised to update to version 3.8.1, which addresses these issues.

Affected Version(s)

coraza < 3.8.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.