CVE-2026-107825
Received Received - Intake

Path Traversal in OWASP Coraza WAF Library

Vulnerability report for CVE-2026-107825, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
corazawaf coraza >= 3.0.0, < 3.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OWASP Coraza WAF versions 3.0.0 to 3.8.0. When a malformed URI containing control bytes (like NUL, CR, LF, or tab) is processed, Go's url.ParseRequestURI fails. The ProcessURI function then drops QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and GET-derived ARGS while keeping REQUEST_URI_RAW intact. This allows attackers to bypass WAF rules targeting query parameters in non-net/http integrations like coraza-spoa or coraza-proxy-wasm.

Detection Guidance

Check Coraza WAF logs for URI parsing errors or malformed request targets containing control bytes like NUL, CR, LF, or tabs. Inspect REQUEST_URI_RAW for suspicious patterns while QUERY_STRING and ARGS_GET remain empty.

Impact Analysis

An unauthenticated attacker could exploit this to bypass security rules that inspect query parameters. Since GET-side rules fail to trigger, malicious payloads in query strings may go undetected. This primarily affects integrations passing raw URIs directly to Coraza, such as custom FFI hosts or WASM hosts. Standard net/http integrations are unaffected as they reject malformed URIs before Coraza processes them.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized data access or manipulation. If query parameters containing sensitive data (e.g., session tokens, PII) are bypassed due to malformed URIs, security rules may fail to detect or block malicious requests. This could lead to unauthorized data exposure or modification, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Upgrade Coraza WAF to version 3.8.0 or later. If upgrading is not possible, apply the patch from commit 0321af96cef18fbafb40980cf075d7cc449a66fa to restore URI parsing fallback and enable rule 200009 to reject malformed URIs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107825. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart