Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107825— OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations

Quick assessment

Affected
corazawaf coraza
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OWASP Coraza WAF 是一个与 ModSecurity 兼容、基于 Go 语言开发的 Web 应用防火墙(WAF)库。在版本 3.0.0 至 3.8.0 之间, 文件中的 函数在处理 解析失败时,仅保留了原始 URI,但将 、 、 以及由 GET 方法派生的 部分置为空。攻击者无需身份认证,即可通过 coraza-spoa、coraza-proxy-wasm、自定义 FFI 主机或 WASM 主机等集成方式,向直接传入的 URI 中注入控制字节。这会导致 Coraza 忽略某些查询参数,而下游集成组件可

CVSS 4.0 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
corazawaf coraza >= 3.0.0, < 3.8.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107825

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
Source: CVE Program / CVE List V5
Vulnerability Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
corazawaf coraza >= 3.0.0, < 3.8.0 -

II. Public POCs for CVE-2026-107825

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107825

请登录查看更多情报信息。

Other References for CVE-2026-107825 (3)

Same Patch Batch · corazawaf · 2026-10-09 · 5 CVEs total

CVE-2026-107826 7.5 HIGH OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-dept
CVE-2026-107833 5.9 MEDIUM OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustio
CVE-2026-107834 5.3 MEDIUM OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart b
CVE-2026-107835 4.0 MEDIUM OWASP Coraza WAF: Cookie Parser Confusion

IV. Related Vulnerabilities

V. Comments for CVE-2026-107825

No comments yet


Leave a comment