Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.
Published: 2026-10-09
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises from an unbounded recursion in the JSON response body processor of OWASP Coraza WAF. When a deeply nested JSON payload is returned by the protected application, the processor, using an ignoreJSONRecursionLimit of -1, performs quadratic work that can lock a CPU core for several seconds per response, leading to noticeable performance degradation and potentially denial of service.

Affected Systems

OWASP Coraza WAF versions 3.0.0 through 3.7.x are affected. The issue is resolved in release 3.8.0. Users running the vulnerable configurations should verify their installed version and plan an upgrade or apply the corresponding patch.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate impact, and the EPSS score is not available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to be able to influence the response that the WAF processes and must have response-body inspection enabled. A network attacker who can make the protected service return a deeply nested JSON can trigger CPU exhaustion, but the problem does not affect request JSON processing or other components of the WAF.

Generated by OpenCVE AI on October 9, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OWASP Coraza WAF to version 3.8.0 or later, which contains the fixed JSON response body processor.
  • If upgrading immediately is not possible, disable response‑body inspection for applications where it is not essential to reduce exposure.
  • When disabling is infeasible, enforce a stricter maximum JSON recursion limit for response bodies to limit resource consumption.

Generated by OpenCVE AI on October 9, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3c6w-j9xm-8h2h Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
History

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.
Title OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T18:02:08.775Z

Reserved: 2026-10-08T22:34:49.288Z

Link: CVE-2026-107833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:04.847

Modified: 2026-10-09T18:17:04.847

Link: CVE-2026-107833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T18:30:11Z

Weaknesses