corazawaf has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was October 2026 with 3. The median CVSS is 5.8 (medium).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- github.com/corazawaf/coraza/v3 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-41510High· 7.2Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding40CVE-2026-41508Medium· 5.8Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling32CVE-2026-41504Medium· 5.8Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields32
corazawaf vulnerabilities
CVEs affecting corazawaf, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-41504Medium· 5.8Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
▾ Sunlitcorazawaf · github.com/corazawaf/coraza/v3via OSV
CVE-2026-41510High· 7.2Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
▾ Twilightcorazawaf · github.com/corazawaf/coraza/v3via OSV
CVE-2026-41508Medium· 5.8Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
▾ Sunlitcorazawaf · github.com/corazawaf/coraza/v3via OSV