PT-2026-107377 · Coraza · Coraza
CVE-2026-41510
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Coraza versions 3.0.0 through 3.8.0
Description
Coraza contains a flaw where request arguments are silently discarded once the
SecArgumentsLimit (default 1000) is reached. Because the engine does not set an error flag or notify rules when this limit is hit, an attacker can bypass security rules targeting ARGS, ARGS GET, ARGS NAMES, ARGS GET NAMES, or ARGS PATH by padding the request with filler arguments. In some versions, the order of discarded arguments is non-deterministic, allowing a malicious payload to be hidden from inspection through repeated attempts.Additionally, the software has several memory-related issues:
- The POST urlencoded body processor previously ignored the argument limit, allowing
ARGS POSTto grow unbounded. - The JSON body processor lacked enforcement of the argument limit, enabling memory exhaustion via large flat JSON arrays.
- A byte-budget bypass existed in the JSON flattening process where array-length summary entries were not checked against the
byteBudget, potentially leading to significant memory amplification and CPU exhaustion.
Technical details include vulnerabilities in the
AddGetRequestArgument, AddPostRequestArgument, and AddPathRequestArgument functions, as well as the ExtractGetArguments function and the internal/bodyprocessors/urlencoded.go and internal/bodyprocessors/json.go files.Recommendations
Update Coraza to version 3.8.1.
As a temporary mitigation, implement security rules to deny requests where the count of
ARGS GET, ARGS POST, or ARGS PATH exceeds the configured SecArgumentsLimit.Fix
Allocation of Resources Without Limits
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coraza