PT-2026-107377 · Coraza · Coraza

CVE-2026-41510

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Coraza versions 3.0.0 through 3.8.0
Description Coraza contains a flaw where request arguments are silently discarded once the SecArgumentsLimit (default 1000) is reached. Because the engine does not set an error flag or notify rules when this limit is hit, an attacker can bypass security rules targeting ARGS, ARGS GET, ARGS NAMES, ARGS GET NAMES, or ARGS PATH by padding the request with filler arguments. In some versions, the order of discarded arguments is non-deterministic, allowing a malicious payload to be hidden from inspection through repeated attempts.
Additionally, the software has several memory-related issues:
  • The POST urlencoded body processor previously ignored the argument limit, allowing ARGS POST to grow unbounded.
  • The JSON body processor lacked enforcement of the argument limit, enabling memory exhaustion via large flat JSON arrays.
  • A byte-budget bypass existed in the JSON flattening process where array-length summary entries were not checked against the byteBudget, potentially leading to significant memory amplification and CPU exhaustion.
Technical details include vulnerabilities in the AddGetRequestArgument, AddPostRequestArgument, and AddPathRequestArgument functions, as well as the ExtractGetArguments function and the internal/bodyprocessors/urlencoded.go and internal/bodyprocessors/json.go files.
Recommendations Update Coraza to version 3.8.1. As a temporary mitigation, implement security rules to deny requests where the count of ARGS GET, ARGS POST, or ARGS PATH exceeds the configured SecArgumentsLimit.

Fix

Allocation of Resources Without Limits

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41510
GHSA-6R3Q-MJV7-XR8M

Affected Products

Coraza