PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107825 corazawaf CVE debrief

A defense-in-depth bypass issue exists in OWASP Coraza WAF versions 3.0.0 through 3.8.0. When ProcessURI fails to parse a URI, it retains the raw URI but omits query parameters, potentially allowing attackers to bypass rules targeting those variables in non-net/http integrations. This issue can have significant operational impacts, including potential bypass of security rules and increased risk to affected systems. Defenders should prioritize verifying exposure and applying version 3.8.0 or later to mitigate this vulnerability.

Vendor
corazawaf
Product
coraza
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders using OWASP Coraza WAF in non-net/http integrations should verify exposure and apply version 3.8.0 or later. This includes operators of web applications protected by Coraza WAF, security teams responsible for vulnerability management, and platform administrators who integrate Coraza WAF with custom or third-party components. Prioritizing verification and updates will help mitigate the defense-in-depth bypass issue and reduce the risk of potential

Why it matters

A defense-in-depth bypass issue exists in OWASP Coraza WAF versions 3.0.0 through 3.8.0, potentially allowing attackers to bypass rules targeting query parameters in non-net/http integrations. Defenders should prioritize verifying exposure and applying version 3.8.0 or later.

  • Verify exposure in non-net/http integrations
  • Potential bypass of rules targeting query parameters
  • Prioritize updating to version 3.8.0 or later
  • Monitor for potential bypass attempts

Technical summary

OWASP Coraza WAF versions 3.0.0-3.8.0 have a defense-in-depth bypass issue. When ProcessURI fails to parse a URI, it retains the raw URI but omits query parameters, potentially allowing attackers to bypass rules targeting those variables in non-net/http integrations. This issue arises from the library's handling of malformed URI requests, which can be exploited by unauthenticated attackers. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza.

Defensive priority

Defenders should prioritize verifying exposure in non-net/http integrations using Coraza WAF versions 3.0.0-3.8.0 and applying version 3.8.0 or later.

Recommended defensive actions

  • Verify Coraza WAF version and update to 3.8.0 or later if using a non-net/http integration
  • Review non-net/http integrations for potential exposure to the defense-in-depth bypass
  • Monitor for potential bypass attempts in non-net/http integrations
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the issue, affected versions, and fixed version. Limited information is available on potential exploitation or victim impact. The issue is confirmed to affect OWASP Coraza WAF versions 3.0.0 through 3.8.0, and defenders should verify exposure in their environments. The CVE Program record and NVD detail page offer additional context on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107825 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107825

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107825 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107825

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — def

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107825.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.