Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.
Published: 2026-10-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Deferring the closure of temporary files for each multipart component keeps file descriptors open until the entire request completes. An unauthenticated attacker can send a multipart body with many minimal parts, causing the process to exhaust its file‑descriptor table. The failure to create new temporary files triggers multipart strict error responses, blocks legitimate uploads, and can make the process unable to open any files or sockets, effectively denying service to other traffic.

Affected Systems

The vulnerability affects the Coraza web application firewall library, versions 3.0.0 through 3.8.0. Any deployment of Coraza before the 3.8.0 release that handles multipart HTTP requests is susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, so the likelihood of exploitation is uncertain but possible, especially for heavily used web services. The vulnerability is not listed in CISA’s KEV catalog. An attacker does not need authentication and can trigger the exploit via a standard HTTP multipart POST to the protected endpoint.

Generated by OpenCVE AI on October 9, 2026 at 18:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Coraza to version 3.8.0 or later, which closes temporary files promptly.
  • If an upgrade cannot be performed immediately, limit the maximum size of multipart requests or enforce stricter upload size limits to reduce the number of temporary files created.
  • Monitor the process’s file descriptor usage for anomalous growth and consider alerting when it approaches the system limit.

Generated by OpenCVE AI on October 9, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rp9v-7xv3-r6g3 Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
History

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.
Title OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor
Weaknesses CWE-400
CWE-772
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:41:07.802Z

Reserved: 2026-10-08T22:34:49.289Z

Link: CVE-2026-107834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:05.007

Modified: 2026-10-09T18:17:05.007

Link: CVE-2026-107834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T18:30:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-772

    Missing Release of Resource after Effective Lifetime