PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107835 corazawaf CVE debrief

A vulnerability in OWASP Coraza WAF's cookie parser allows an unauthenticated attacker to craft a Cookie header that may cause the WAF to index or drop a cookie under a different name or value than the backend application. This issue is fixed in version 3.8.1. The vulnerability affects OWASP Coraza WAF versions prior to 3.8.1, and defenders should assess exposure and prioritize remediation. The issue involves the internal/cookies.ParseCookies function handling boundary ASCII control characters and control-only or empty cookie names differently than several backend cookie parsers.

Vendor
corazawaf
Product
coraza
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-10
Advisory published
2026-10-08
Advisory updated
2026-10-10

Who should care

Defenders using Coraza WAF versions prior to 3.8.1 should assess exposure and prioritize remediation. Those responsible for WAF configuration, security monitoring, and incident response should review the vulnerability and its potential impact.

Why it matters

Defenders should care about CVE-2026-107835 because it affects OWASP Coraza WAF's cookie parser, potentially causing WAF to miss attacker data or drop cookies. Those using Coraza WAF versions prior to 3.8.1 should assess exposure and prioritize remediation.

  • Potential for WAF to miss application-visible attacker data.
  • Possible cookie indexing or dropping under different names or values.
  • Need for verification of backend parser and WAF rule scope.
  • Remediation priority for Coraza WAF versions prior to 3.8.1.

Technical summary

OWASP Coraza WAF's internal/cookies.ParseCookies function handles boundary ASCII control characters and control-only or empty cookie names differently than several backend cookie parsers. An unauthenticated attacker can craft a Cookie header to cause Coraza to index or drop a cookie under a different name or value than the backend application. The issue affects OWASP Coraza WAF versions prior to 3.8.1, and defenders should assess exposure and prioritize remediation. The vulnerability is confirmed by multiple sources, including the CVE Program and NIST NVD.

Defensive priority

Defenders should prioritize assessment and remediation of this vulnerability, especially those using Coraza WAF versions prior to 3.8.1.

Recommended defensive actions

  • Assess exposure to CVE-2026-107835 by checking if Coraza WAF versions prior to 3.8.1 are in use.
  • Verify that Coraza WAF is updated to version 3.8.1 or later.
  • Review backend parser and WAF rule scope to understand potential impact.
  • Monitor for unusual cookie handling behavior.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on the vulnerability, its impact, and the fixed version. The vulnerability is confirmed by multiple sources, including the CVE Program and NIST NVD. The issue affects OWASP Coraza WAF versions prior to 3.8.1, and defenders should verify the backend parser and WAF rule scope to understand potential impact. The source item and CVE record provide evidence of the vulnerability and its effects.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107835 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107835

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107835 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107835

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • OWASP Coraza WAF: Cookie Parser Confusion

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107835.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.1

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.