PatchSiren cyber security CVE debrief
CVE-2026-41504 corazawaf CVE debrief
CVE-2026-41504 is a vulnerability in the Coraza web application firewall (WAF) that allows for CRLF injection and log forgery via request body and header fields in the Native audit-log format. This issue arises from the lack of escaping of `r` and `n` characters in the log output, which can be exploited by an attacker to inject fake log lines. The vulnerability affects the Native format's section structure, which is line-based and delimited by lines of the form `--<10-char-random-prefix>-<Part>--`. Any attacker-controlled bytes containing `n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. Defenders who use Coraza WAF in
- Vendor
- corazawaf
- Product
- coraza
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-06
Who should care
Defenders who use Coraza WAF in their environment should be aware of this vulnerability and take steps to verify the affected versions and update to a fixed version. They should also review their log parsing and SIEM rules to ensure they are not vulnerable to log injection attacks.
Why it matters
This vulnerability allows an attacker to inject fake log lines into the Coraza WAF's Native audit-log format, potentially leading to confusion or incorrect incident response. Defenders should prioritize verifying the affected versions and updating to a fixed version, as well as reviewing their log parsing and SIEM rules.
- An attacker could inject fake log lines, potentially leading to confusion or incorrect incident response
- An attacker could hide malicious activity from logs
- Defenders may need to verify the integrity of their logs
- Defenders should prioritize updating to a fixed version of Coraza
Technical summary
The Coraza WAF's Native audit-log format implementation is vulnerable to CRLF injection and log forgery attacks. This is due to the lack of escaping of `r` and `n` characters in the log output, which allows an attacker to inject fake log lines. The vulnerability affects the Native format's section structure, which is line-based and delimited by lines of the form `--<10-char-random-prefix>-<Part>--`. Any attacker-controlled bytes containing `n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. The JSON formatter (`formats_json.go`) and other
Defensive priority
Defenders should prioritize verifying the affected versions of Coraza in their environment and updating to version 3.8.0 or later. They should also review their log parsing and SIEM rules to ensure they are not vulnerable to log injection attacks.
Recommended defensive actions
- Verify the version of Coraza in use and update to version 3.8.0 or later if necessary
- Review log parsing and SIEM rules to ensure they are not vulnerable to log injection attacks
- Monitor logs for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by the lack of escaping of `r` and `n` characters in the Native audit-log format implementation in Coraza. This allows an attacker to inject fake log lines by including `n` characters in the request body or header fields.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41504 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41504
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41504 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41504
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and heade
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-prpw-wwv7-xjjr.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-prpw-wwv7-xjjr
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/a3079325547c7c1e08522aed4d6468f25d080e25
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.