CVE-2026-107833
Received Received - Intake

Path Traversal in OWASP Coraza WAF Response Processing

Vulnerability report for CVE-2026-107833, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
corazawaf coraza >= 3.0.0, < 3.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in OWASP Coraza WAF, a web application firewall library. It involves a flaw in the ProcessResponse function where a value of -1 is passed to readJSON, bypassing a recursion limit check. This allows deeply nested JSON responses to cause quadratic processing time, consuming CPU resources for seconds per response.

Detection Guidance

This vulnerability can be detected by checking the version of OWASP Coraza WAF in use. If the version is between 3.0.0 and 3.8.0, the system is vulnerable. Run: coraza version to check the installed version.

Impact Analysis

An attacker could exploit this by sending deeply nested JSON responses to an application protected by Coraza. This would cause high CPU usage, potentially leading to degraded performance or denial of service for the application.

Compliance Impact

This vulnerability primarily causes CPU exhaustion via denial-of-service (DoS) attacks, which could lead to service unavailability. GDPR and HIPAA require maintaining system availability and protecting data integrity. While this CVE does not directly impact data confidentiality or privacy, prolonged DoS conditions could disrupt compliance by preventing access to critical systems handling personal or health data.

Mitigation Strategies

Upgrade OWASP Coraza WAF to version 3.8.0 or later to address the vulnerability. If upgrading is not immediately possible, disable response-body inspection or set a lower recursion limit as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107833. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart