PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107833 corazawaf CVE debrief

A vulnerability in OWASP Coraza WAF, a golang modsecurity compatible web application firewall library, allows for CPU exhaustion through unbounded recursion in the JSON response body processor. This issue, affecting versions 3.0.0 through 3.8.0, can be triggered by a network attacker causing an application protected by Coraza to return deeply nested JSON, leading to quadratic work consumption of one CPU core for seconds per response within the default ResponseBodyLimit.

Vendor
corazawaf
Product
coraza
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders and security teams using OWASP Coraza WAF for protecting web applications should assess their exposure to this vulnerability, especially if they are using versions between 3.0.0 and 3.8.0 and have response-body inspection enabled.

Why it matters

This vulnerability in OWASP Coraza WAF can lead to CPU exhaustion through unbounded recursion in JSON response body processing. Defenders should assess exposure, particularly for versions 3.0.0 to 3.8.0 with response-body inspection enabled, and prioritize upgrading to version 3.8.0 or later.

  • Potential for CPU exhaustion leading to denial of service
  • Increased resource consumption for Coraza-protected applications
  • Need for verification of current Coraza version and exposure to deeply nested JSON responses
  • Priority for upgrading to version 3.8.0 or later

Technical summary

The vulnerability lies in the ProcessResponse function in internal/bodyprocessors/json.go, where the ignoreJSONRecursionLimit value of -1 is passed to readJSON. This causes the recursive guard to stop only at zero, allowing for quadratic work consumption when processing deeply nested JSON responses. The issue requires response-body inspection to be enabled and does not affect request JSON processing.

Defensive priority

Defenders should prioritize assessing exposure and applying remediation for this vulnerability, particularly for systems using Coraza for response-body inspection.

Recommended defensive actions

  • Assess exposure of Coraza instances to potential deeply nested JSON responses
  • Verify if response-body inspection is enabled and adjust configurations if necessary
  • Prioritize upgrading to Coraza version 3.8.0 or later
  • Monitor for unusual CPU consumption patterns in Coraza-protected applications
  • Perform an inventory of assets using Coraza for response-body inspection
  • Review change management windows for applying Coraza updates
  • Track and verify Coraza version updates in vulnerability management systems

Evidence notes

The vulnerability is confirmed in Coraza versions from 3.0.0 up to but not including 3.8.0. The issue is fixed in version 3.8.0. Official sources include the CVE Program record and the NIST NVD detail page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107833 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107833

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107833 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107833

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhaustion

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107833.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.