PatchSiren cyber security CVE debrief
CVE-2026-107835 corazawaf CVE debrief
A vulnerability in OWASP Coraza WAF's cookie parser allows an unauthenticated attacker to craft a Cookie header that may cause the WAF to index or drop a cookie under a different name or value than the backend application. This issue is fixed in version 3.8.1. The vulnerability affects OWASP Coraza WAF versions prior to 3.8.1, and defenders should assess exposure and prioritize remediation. The issue involves the internal/cookies.ParseCookies function handling boundary ASCII control characters and control-only or empty cookie names differently than several backend cookie parsers.
- Vendor
- corazawaf
- Product
- coraza
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-10
Who should care
Defenders using Coraza WAF versions prior to 3.8.1 should assess exposure and prioritize remediation. Those responsible for WAF configuration, security monitoring, and incident response should review the vulnerability and its potential impact.
Why it matters
Defenders should care about CVE-2026-107835 because it affects OWASP Coraza WAF's cookie parser, potentially causing WAF to miss attacker data or drop cookies. Those using Coraza WAF versions prior to 3.8.1 should assess exposure and prioritize remediation.
- Potential for WAF to miss application-visible attacker data.
- Possible cookie indexing or dropping under different names or values.
- Need for verification of backend parser and WAF rule scope.
- Remediation priority for Coraza WAF versions prior to 3.8.1.
Technical summary
OWASP Coraza WAF's internal/cookies.ParseCookies function handles boundary ASCII control characters and control-only or empty cookie names differently than several backend cookie parsers. An unauthenticated attacker can craft a Cookie header to cause Coraza to index or drop a cookie under a different name or value than the backend application. The issue affects OWASP Coraza WAF versions prior to 3.8.1, and defenders should assess exposure and prioritize remediation. The vulnerability is confirmed by multiple sources, including the CVE Program and NIST NVD.
Defensive priority
Defenders should prioritize assessment and remediation of this vulnerability, especially those using Coraza WAF versions prior to 3.8.1.
Recommended defensive actions
- Assess exposure to CVE-2026-107835 by checking if Coraza WAF versions prior to 3.8.1 are in use.
- Verify that Coraza WAF is updated to version 3.8.1 or later.
- Review backend parser and WAF rule scope to understand potential impact.
- Monitor for unusual cookie handling behavior.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability, its impact, and the fixed version. The vulnerability is confirmed by multiple sources, including the CVE Program and NIST NVD. The issue affects OWASP Coraza WAF versions prior to 3.8.1, and defenders should verify the backend parser and WAF rule scope to understand potential impact. The source item and CVE record provide evidence of the vulnerability and its effects.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107835 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107835
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107835 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107835
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
OWASP Coraza WAF: Cookie Parser Confusion
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107835.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-g4qm-m288-5cp9
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.1
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.