CVE-2026-107826High· 7.5▾ TwilightOWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte b…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.1Patched in:
github.com/corazawaf/coraza/v3 3.8.1Connected by shared product, vendor, weakness, or advisory.
GHSA-6gcq-wc29-5xf2High· 7.5Coraza JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)
CVE-2026-41510High· 7.2Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
CVE-2026-107833Medium· 5.9OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
GHSA-5gj4-9gm7-2fx2Medium· 5.8Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
GHSA-g4qm-m288-5cp9Medium· 4.0Coraza has Cookie Parser Confusion
GHSA-3c6w-j9xm-8h2hMedium· 5.9Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion