PatchSiren cyber security CVE debrief
CVE-2026-107833 corazawaf CVE debrief
A vulnerability in OWASP Coraza WAF, a golang modsecurity compatible web application firewall library, allows for CPU exhaustion through unbounded recursion in the JSON response body processor. This issue, affecting versions 3.0.0 through 3.8.0, can be triggered by a network attacker causing an application protected by Coraza to return deeply nested JSON, leading to quadratic work consumption of one CPU core for seconds per response within the default ResponseBodyLimit.
- Vendor
- corazawaf
- Product
- coraza
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders and security teams using OWASP Coraza WAF for protecting web applications should assess their exposure to this vulnerability, especially if they are using versions between 3.0.0 and 3.8.0 and have response-body inspection enabled.
Why it matters
This vulnerability in OWASP Coraza WAF can lead to CPU exhaustion through unbounded recursion in JSON response body processing. Defenders should assess exposure, particularly for versions 3.0.0 to 3.8.0 with response-body inspection enabled, and prioritize upgrading to version 3.8.0 or later.
- Potential for CPU exhaustion leading to denial of service
- Increased resource consumption for Coraza-protected applications
- Need for verification of current Coraza version and exposure to deeply nested JSON responses
- Priority for upgrading to version 3.8.0 or later
Technical summary
The vulnerability lies in the ProcessResponse function in internal/bodyprocessors/json.go, where the ignoreJSONRecursionLimit value of -1 is passed to readJSON. This causes the recursive guard to stop only at zero, allowing for quadratic work consumption when processing deeply nested JSON responses. The issue requires response-body inspection to be enabled and does not affect request JSON processing.
Defensive priority
Defenders should prioritize assessing exposure and applying remediation for this vulnerability, particularly for systems using Coraza for response-body inspection.
Recommended defensive actions
- Assess exposure of Coraza instances to potential deeply nested JSON responses
- Verify if response-body inspection is enabled and adjust configurations if necessary
- Prioritize upgrading to Coraza version 3.8.0 or later
- Monitor for unusual CPU consumption patterns in Coraza-protected applications
- Perform an inventory of assets using Coraza for response-body inspection
- Review change management windows for applying Coraza updates
- Track and verify Coraza version updates in vulnerability management systems
Evidence notes
The vulnerability is confirmed in Coraza versions from 3.0.0 up to but not including 3.8.0. The issue is fixed in version 3.8.0. Official sources include the CVE Program record and the NIST NVD detail page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107833 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107833
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107833 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107833
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107833.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.