github.com/corazawaf/coraza/v3
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/corazawaf/coraza/v3page 1 of 1
- CVE-2023-40586HIGHCVSS 7.5EG 7.5fixed in 3.0.12023-08-25
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately…
- CVE-2025-29914MEDIUMCVSS 5.4EG 5.4fixed in 3.3.32025-03-20
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads…
- CVE-2026-107825MEDIUMCVSS 4.0EG 4.0fixed in 3.8.02026-10-09
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_…
- CVE-2026-107826HIGHCVSS 7.5EG 7.5fixed in 3.8.12026-10-09
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte bud…
- CVE-2026-107833MEDIUMCVSS 5.9EG 5.9fixed in 3.8.02026-10-09
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursi…
- CVE-2026-107834MEDIUMCVSS 5.3EG 5.3fixed in 3.8.02026-10-09
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temp…
- CVE-2026-107835MEDIUMCVSS 4.0EG 4.0fixed in 3.8.12026-10-09
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie n…
Check whether github.com/corazawaf/coraza/v3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/corazawaf/coraza/v3 CVEs against the assets you own.
Book a Demo →