OWASP Coraza WAF 是一个与 ModSecurity 兼容的、使用 Go 语言实现的 Web 应用程序防火墙(WAF)库。在版本 3.0.0 至 3.8.0 之间, 文件中的 函数将 值设置为 -1,并将其传递给 函数,而递归保护机制仅在检测到值为 0 时才停止。如果网络攻击者能够致使受 Coraza 保护的应用程序返回深层嵌套的 JSON 响应,则会导致响应体处理执行二次复杂度(quadratic complexity)的计算操作,在默认 ResponseBodyLimit 限制下,每个响应可能消耗
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107826 | 7.5 HIGH | OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-dept |
| CVE-2026-107834 | 5.3 MEDIUM | OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart b |
| CVE-2026-107825 | 4.0 MEDIUM | OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure |
| CVE-2026-107835 | 4.0 MEDIUM | OWASP Coraza WAF: Cookie Parser Confusion |
No comments yet