OWASP Coraza WAF 是一个与 ModSecurity 兼容、基于 Go 语言开发的 Web 应用防火墙(WAF)库。在版本 3.0.0 至 3.8.0 之间, 文件中的 函数在处理 解析失败时,仅保留了原始 URI,但将 、 、 以及由 GET 方法派生的 部分置为空。攻击者无需身份认证,即可通过 coraza-spoa、coraza-proxy-wasm、自定义 FFI 主机或 WASM 主机等集成方式,向直接传入的 URI 中注入控制字节。这会导致 Coraza 忽略某些查询参数,而下游集成组件可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107826 | 7.5 HIGH | OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-dept |
| CVE-2026-107833 | 5.9 MEDIUM | OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustio |
| CVE-2026-107834 | 5.3 MEDIUM | OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart b |
| CVE-2026-107835 | 4.0 MEDIUM | OWASP Coraza WAF: Cookie Parser Confusion |
No comments yet