github.com/corazawaf/coraza/v3 vulnerabilities
CVEs whose affected-version data names the github.com/corazawaf/coraza/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-41504Medium· 5.8Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
▾ Sunlitcorazawaf · github.com/corazawaf/coraza/v3via OSV
CVE-2026-41510High· 7.2Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
▾ Twilightcorazawaf · github.com/corazawaf/coraza/v3via OSV
CVE-2026-41508Medium· 5.8Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
▾ Sunlitcorazawaf · github.com/corazawaf/coraza/v3via OSV