CVE-2026-107835
Received Received - Intake

Cookie Header Parsing Issue in OWASP Coraza WAF

Vulnerability report for CVE-2026-107835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
corazawaf coraza < 3.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107835 is a vulnerability in OWASP Coraza WAF versions prior to 3.8.1 where the cookie parser mishandles ASCII control characters in cookie names and values. This causes Coraza and backend applications to interpret cookies differently, allowing attackers to craft cookies that evade WAF inspection by bypassing rules targeting specific cookie names or values.

Detection Guidance

To detect this vulnerability, check the version of Coraza WAF installed on your system. Run: coraza version. If the version is below 3.8.1, the system is vulnerable. Inspect HTTP request logs for cookies with control characters adjacent to the equals sign (e.g., a\v=\t').

Use WAF rule testing tools to simulate malicious cookie headers and verify if rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES are bypassed. Monitor for unexpected cookie parsing behavior in backend applications.

Impact Analysis

An attacker could exploit this to bypass security rules in Coraza WAF, potentially hiding malicious payloads in cookies that go undetected. This may allow unauthorized access or data exfiltration if backend systems process the malformed cookies differently than Coraza expects.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating confidentiality requirements under GDPR and HIPAA. Non-compliance may result if WAF rules fail to detect malicious activity due to the bypass.

Mitigation Strategies

Upgrade Coraza WAF to version 3.8.1 or later immediately. This addresses the cookie parsing flaw and ensures compliance with RFC 6265. Verify the upgrade by running coraza version again.

Review and update WAF rules to account for stricter cookie parsing. Ensure rules inspect cookies with empty names or control characters properly. Test changes in a staging environment before production deployment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart