PT-2026-109277 · Owasp · Coraza Waf+2
CVE-2026-107825
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
4.0
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OWASP Coraza WAF versions 3.0.0 through 3.7.0
Description
An issue exists in the
ProcessURI() function within internal/corazawaf/transaction.go where the library fails to properly handle URIs containing raw control bytes (such as x00, , r, or t). When the url.ParseRequestURI() function returns an error due to these bytes, the system retains the raw URI but leaves the QUERY STRING, ARGS GET, ARGS GET NAMES, and the GET-derived portion of ARGS empty.An unauthenticated attacker can exploit this by placing control bytes in a URI. This causes the WAF to omit query parameters that downstream integrations may still process, allowing security rules targeting those variables to be bypassed. This specifically affects integrations that forward raw URI bytes directly to
ProcessURI(), such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts. The standard coraza/v3/http integration is not affected as Go's net/http rejects such malformed requests before they reach the library.Recommendations
Update OWASP Coraza WAF to version 3.8.0.
As a temporary mitigation, restrict access to or monitor traffic passing through
coraza-spoa, coraza-proxy-wasm, and custom FFI/WASM hosts to identify malformed URIs.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coraza Waf
Coraza-Proxy-Wasm
Coraza-Spoa