Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.
Published: 2026-10-09
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: Bypass of request validation rules
Action: Patch
AI Analysis

Impact

The vulnerability arises in Coraza's ProcessURI function, which when URL parsing fails, drops the QUERY_STRING and ARGS_GET data from the request. An unauthenticated attacker can send a request with control bytes that cause parsing to fail, resulting in the downstream integration receiving a request missing its query parameters. This allows malicious actors to bypass security rules that rely on those variables, effectively undermining defense-in-depth controls.

Affected Systems

The affected product is the Coraza web application firewall library, versions 3.0.0 through 3.7.x. The flaw is present in integrations that forward raw URIs to Coraza, such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, and WASM hosts. The bundled coraza/v3/http integration is not impacted because Go net/http rejects malformed requests before they reach Coraza.

Risk and Exploitability

The CVSS score of 4 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an unauthenticated attacker sending a malformed URI to a vulnerable integration, which then forwards it to Coraza. If successful, the attacker can cause query parameters to be stripped and rule checks that depend on those parameters to be bypassed. The overall risk is moderate as it requires a specific integration path but can be severe if rules rely heavily on query variables.

Generated by OpenCVE AI on October 9, 2026 at 18:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Coraza to version 3.8.0 or later, where the issue is fixed.
  • Ensure that any custom integration—such as coraza-spoa, coraza-proxy-wasm, custom FFI or WASM hosts—rejects malformed URIs before passing them to Coraza.
  • If immediate upgrade is not possible, add a preliminary check on the raw URI to reject malformed requests and preserve the original query parameters for downstream processing.

Generated by OpenCVE AI on October 9, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x26q-wvhg-fh4m Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
History

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.
Title OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
Weaknesses CWE-20
CWE-436
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:32:11.506Z

Reserved: 2026-10-08T21:23:59.824Z

Link: CVE-2026-107825

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:04.503

Modified: 2026-10-09T18:17:04.503

Link: CVE-2026-107825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T18:30:11Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-436

    Interpretation Conflict