PT-2026-109277 · Owasp · Coraza Waf+2

CVE-2026-107825

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

4.0

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OWASP Coraza WAF versions 3.0.0 through 3.7.0
Description An issue exists in the ProcessURI() function within internal/corazawaf/transaction.go where the library fails to properly handle URIs containing raw control bytes (such as x00, , r, or t). When the url.ParseRequestURI() function returns an error due to these bytes, the system retains the raw URI but leaves the QUERY STRING, ARGS GET, ARGS GET NAMES, and the GET-derived portion of ARGS empty.
An unauthenticated attacker can exploit this by placing control bytes in a URI. This causes the WAF to omit query parameters that downstream integrations may still process, allowing security rules targeting those variables to be bypassed. This specifically affects integrations that forward raw URI bytes directly to ProcessURI(), such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts. The standard coraza/v3/http integration is not affected as Go's net/http rejects such malformed requests before they reach the library.
Recommendations Update OWASP Coraza WAF to version 3.8.0. As a temporary mitigation, restrict access to or monitor traffic passing through coraza-spoa, coraza-proxy-wasm, and custom FFI/WASM hosts to identify malformed URIs.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107825
GHSA-X26Q-WVHG-FH4M

Affected Products

Coraza Waf
Coraza-Proxy-Wasm
Coraza-Spoa