OWASP Coraza WAF 是一个与 ModSecurity 兼容的、基于 Go 语言实现的 Web 应用防火墙(WAF)库。在 3.8.1 版本之前, 函数(位于 文件中)在处理边界 ASCII 控制字符,以及仅包含控制字符或为空的 Cookie 名称时,其行为与多个后端 Cookie 解析器存在差异。未经身份验证的攻击者可以构造特定的 Cookie 头部,使得 Coraza 对 Cookie 的索引或丢弃方式与后端应用程序所识别的名称或值不一致,从而导致针对 或 的检测规则无法捕获攻击者实际发送至后端的应
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107826 | 7.5 HIGH | OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-dept |
| CVE-2026-107833 | 5.9 MEDIUM | OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustio |
| CVE-2026-107834 | 5.3 MEDIUM | OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart b |
| CVE-2026-107825 | 4.0 MEDIUM | OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure |
No comments yet