PatchSiren cyber security CVE debrief
CVE-2026-107825 corazawaf CVE debrief
A defense-in-depth bypass issue exists in OWASP Coraza WAF versions 3.0.0 through 3.8.0. When ProcessURI fails to parse a URI, it retains the raw URI but omits query parameters, potentially allowing attackers to bypass rules targeting those variables in non-net/http integrations. This issue can have significant operational impacts, including potential bypass of security rules and increased risk to affected systems. Defenders should prioritize verifying exposure and applying version 3.8.0 or later to mitigate this vulnerability.
- Vendor
- corazawaf
- Product
- coraza
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders using OWASP Coraza WAF in non-net/http integrations should verify exposure and apply version 3.8.0 or later. This includes operators of web applications protected by Coraza WAF, security teams responsible for vulnerability management, and platform administrators who integrate Coraza WAF with custom or third-party components. Prioritizing verification and updates will help mitigate the defense-in-depth bypass issue and reduce the risk of potential
Why it matters
A defense-in-depth bypass issue exists in OWASP Coraza WAF versions 3.0.0 through 3.8.0, potentially allowing attackers to bypass rules targeting query parameters in non-net/http integrations. Defenders should prioritize verifying exposure and applying version 3.8.0 or later.
- Verify exposure in non-net/http integrations
- Potential bypass of rules targeting query parameters
- Prioritize updating to version 3.8.0 or later
- Monitor for potential bypass attempts
Technical summary
OWASP Coraza WAF versions 3.0.0-3.8.0 have a defense-in-depth bypass issue. When ProcessURI fails to parse a URI, it retains the raw URI but omits query parameters, potentially allowing attackers to bypass rules targeting those variables in non-net/http integrations. This issue arises from the library's handling of malformed URI requests, which can be exploited by unauthenticated attackers. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza.
Defensive priority
Defenders should prioritize verifying exposure in non-net/http integrations using Coraza WAF versions 3.0.0-3.8.0 and applying version 3.8.0 or later.
Recommended defensive actions
- Verify Coraza WAF version and update to 3.8.0 or later if using a non-net/http integration
- Review non-net/http integrations for potential exposure to the defense-in-depth bypass
- Monitor for potential bypass attempts in non-net/http integrations
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the issue, affected versions, and fixed version. Limited information is available on potential exploitation or victim impact. The issue is confirmed to affect OWASP Coraza WAF versions 3.0.0 through 3.8.0, and defenders should verify exposure in their environments. The CVE Program record and NVD detail page offer additional context on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107825 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107825
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107825 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107825
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — def
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107825.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.