CVE-2026-107834
Received Received - Intake

Remote File Descriptor Exhaustion in OWASP Coraza WAF

Vulnerability report for CVE-2026-107834, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
corazawaf coraza >= 3.0.0, < 3.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OWASP Coraza WAF (versions 3.0.0 to 3.8.0) involves improper handling of temporary files during multipart form data processing. When processing multipart requests, the system defers closing temporary files until the entire request completes. Each file part in the request keeps a file descriptor open, which can exhaust the system's file descriptor limit if many parts are included. This leads to resource exhaustion and potential denial of service.

Detection Guidance

Monitor for high file descriptor usage during multipart uploads. Check for processes with many open file descriptors using 'lsof -p <PID>' or 'ls /proc/<PID>/fd | wc -l'. Look for EMFILE errors in logs indicating file descriptor exhaustion.

Impact Analysis

An attacker can send a crafted multipart request with many minimal file parts to exhaust file descriptors. This causes the WAF to fail opening files or sockets, blocks legitimate uploads, and triggers false positives in security rules. The system may become unresponsive or crash due to resource exhaustion, impacting availability.

Compliance Impact

This vulnerability could lead to service disruptions or inability to process legitimate requests, potentially violating availability requirements in GDPR (Article 32) and HIPAA (Security Rule). Downtime or failed security checks may also impact integrity and confidentiality controls, depending on system configuration.

Mitigation Strategies

Upgrade Coraza WAF to version 3.8.0 or later. If upgrading is not possible, disable multipart upload handling or implement rate limiting on upload endpoints to prevent excessive file part processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107834. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart