Impact
The vulnerability arises in Coraza's ProcessURI function, which when URL parsing fails, drops the QUERY_STRING and ARGS_GET data from the request. An unauthenticated attacker can send a request with control bytes that cause parsing to fail, resulting in the downstream integration receiving a request missing its query parameters. This allows malicious actors to bypass security rules that rely on those variables, effectively undermining defense-in-depth controls.
Affected Systems
The affected product is the Coraza web application firewall library, versions 3.0.0 through 3.7.x. The flaw is present in integrations that forward raw URIs to Coraza, such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, and WASM hosts. The bundled coraza/v3/http integration is not impacted because Go net/http rejects malformed requests before they reach Coraza.
Risk and Exploitability
The CVSS score of 4 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an unauthenticated attacker sending a malformed URI to a vulnerable integration, which then forwards it to Coraza. If successful, the attacker can cause query parameters to be stripped and rule checks that depend on those parameters to be bypassed. The overall risk is moderate as it requires a specific integration path but can be severe if rules rely heavily on query variables.
OpenCVE Enrichment
Github GHSA