Impact
Deferring the closure of temporary files for each multipart component keeps file descriptors open until the entire request completes. An unauthenticated attacker can send a multipart body with many minimal parts, causing the process to exhaust its file‑descriptor table. The failure to create new temporary files triggers multipart strict error responses, blocks legitimate uploads, and can make the process unable to open any files or sockets, effectively denying service to other traffic.
Affected Systems
The vulnerability affects the Coraza web application firewall library, versions 3.0.0 through 3.8.0. Any deployment of Coraza before the 3.8.0 release that handles multipart HTTP requests is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, so the likelihood of exploitation is uncertain but possible, especially for heavily used web services. The vulnerability is not listed in CISA’s KEV catalog. An attacker does not need authentication and can trigger the exploit via a standard HTTP multipart POST to the protected endpoint.
OpenCVE Enrichment
Github GHSA