PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104774 corazawaf CVE debrief

A vulnerability in the Coraza Web Application Firewall (WAF) allows for WAF bypass due to an off-by-one error in the handling of JavaScript octal escape sequences. This issue arises from incorrect parsing of octal escape sequences in the `jsDecode` transformation, leading to corrupted JS-escaped payloads that can bypass WAF rules relying on `jsDecode` for normalization.

Vendor
corazawaf
Product
Coraza WAF
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Security teams responsible for WAF configuration and management should assess exposure and implement compensating controls. Developers and administrators of applications protected by Coraza WAF should verify the integrity of WAF rules and update them to account for the off-by-one error in octal escape sequence handling.

Why it matters

The Coraza WAF vulnerability allows attackers to bypass WAF rules due to an off-by-one error in the handling of JavaScript octal escape sequences. This requires immediate attention from security teams to assess exposure and implement compensating controls.

  • WAF bypass allows attackers to evade detection by WAF rules relying on `jsDecode` for normalization.
  • Attackers can use JavaScript octal escape sequences to encode attack syntax that can be parsed by the target backend.
  • Defenders need to verify the integrity of WAF rules and update them to account for the off-by-one error.
  • Compensating controls such as monitoring for suspicious traffic are necessary to detect and prevent attacks.

Technical summary

The `t:jsDecode` transformation in Coraza WAF contains an off-by-one error when parsing octal escape sequences. This causes `strconv.ParseInt` to fail and return a null byte instead of the decoded value, leading to corrupted JS-escaped payloads that can bypass WAF rules relying on `jsDecode` for normalization. The vulnerability allows attackers to use JavaScript octal escape sequences to encode attack syntax that can be parsed by the target backend but not correctly decoded by the WAF, enabling WAF bypass. Security teams should assess exposure and implement compensating controls. Developers and administrators of applications protected by Coraza WAF should verify the integrity of WAF rules and update them to to

Defensive priority

Defenders should prioritize assessing exposure and implementing compensating controls, as the vulnerability allows attackers to bypass WAF rules. This requires immediate attention from security teams responsible for WAF configuration and management.

Recommended defensive actions

  • Assess exposure by reviewing WAF configurations and identifying potential bypass vulnerabilities.
  • Implement compensating controls to detect and prevent attacks that may bypass WAF rules.
  • Verify the integrity of WAF rules and update them to account for the off-by-one error in octal escape sequence handling.
  • Monitor for suspicious traffic that may indicate attempted WAF bypasses.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is caused by an off-by-one error in the `jsDecode` transformation when parsing octal escape sequences. This results in `strconv.ParseInt` failing and returning a null byte instead of the decoded value. The issue allows attackers to use JavaScript octal escape sequences to encode attack syntax that can be parsed by the target backend but not correctly decoded by the WAF.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104774 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104774

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104774 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104774

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Coraza: jsDecode Off-by-One in Octal Escape Handling Enables WAF Bypass

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-pc5q-qfxp-ggqv.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-pc5q-qfxp-ggqv

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/f9b7afdbcedce7ad814663eaee2e342578ea3bb2

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.