CVE-2026-107826
Received Received - Intake

Unauthenticated Stack Overflow in OWASP Coraza WAF

Vulnerability report for CVE-2026-107826, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
corazawaf coraza >= 3.0.0, < 3.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107826 is a stack overflow vulnerability in OWASP Coraza WAF versions 3.0.0 to 3.8.0. It occurs in the JSON body processor where a bounded flattening walk stops early due to limits but leaves deeply nested JSON tails unprocessed. The gjson.Valid function then processes the entire raw body without depth bounds, causing a fatal stack overflow and crashing the hosting process.

Detection Guidance

To detect this vulnerability, monitor for crashes or high CPU usage in Coraza WAF processes. Check logs for JSON parsing errors or stack overflow messages. Use tools like curl to send test JSON payloads with deep nesting to see if the system crashes. Example: curl -X POST -H 'Content-Type: application/json' -d '{"a":{"a":{"a":{"a":{"a":{"a":{"a":{"a":{"a":{"a":{"a":{"a"

Impact Analysis

An unauthenticated attacker can exploit this to crash the Coraza WAF process, causing a denial-of-service (DoS) condition. The attack requires no privileges or user interaction and can be executed remotely over the network. It may disrupt web services protected by the WAF.

Compliance Impact

This vulnerability primarily causes a denial-of-service (DoS) condition by crashing the Coraza WAF process through a stack overflow. While it does not directly expose or leak data, the resulting service disruption could impact systems subject to GDPR or HIPAA compliance by making protected data temporarily unavailable, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade Coraza WAF to version 3.8.1 or later immediately. If upgrading is not possible, apply the patch from the GitHub commit 814e1898e083d2ff2ceb644382d0da17e930f93f. Temporarily reduce JSON body size limits and argument counts in configuration to minimize risk until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107826. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart