Impact
This vulnerability arises from an unbounded recursion in the JSON response body processor of OWASP Coraza WAF. When a deeply nested JSON payload is returned by the protected application, the processor, using an ignoreJSONRecursionLimit of -1, performs quadratic work that can lock a CPU core for several seconds per response, leading to noticeable performance degradation and potentially denial of service.
Affected Systems
OWASP Coraza WAF versions 3.0.0 through 3.7.x are affected. The issue is resolved in release 3.8.0. Users running the vulnerable configurations should verify their installed version and plan an upgrade or apply the corresponding patch.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate impact, and the EPSS score is not available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to be able to influence the response that the WAF processes and must have response-body inspection enabled. A network attacker who can make the protected service return a deeply nested JSON can trigger CPU exhaustion, but the problem does not affect request JSON processing or other components of the WAF.
OpenCVE Enrichment
Github GHSA