PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41504 corazawaf CVE debrief

CVE-2026-41504 is a vulnerability in the Coraza web application firewall (WAF) that allows for CRLF injection and log forgery via request body and header fields in the Native audit-log format. This issue arises from the lack of escaping of `r` and `n` characters in the log output, which can be exploited by an attacker to inject fake log lines. The vulnerability affects the Native format's section structure, which is line-based and delimited by lines of the form `--<10-char-random-prefix>-<Part>--`. Any attacker-controlled bytes containing `n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. Defenders who use Coraza WAF in

Vendor
corazawaf
Product
coraza
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-06
Advisory published
2026-10-06
Advisory updated
2026-10-06

Who should care

Defenders who use Coraza WAF in their environment should be aware of this vulnerability and take steps to verify the affected versions and update to a fixed version. They should also review their log parsing and SIEM rules to ensure they are not vulnerable to log injection attacks.

Why it matters

This vulnerability allows an attacker to inject fake log lines into the Coraza WAF's Native audit-log format, potentially leading to confusion or incorrect incident response. Defenders should prioritize verifying the affected versions and updating to a fixed version, as well as reviewing their log parsing and SIEM rules.

  • An attacker could inject fake log lines, potentially leading to confusion or incorrect incident response
  • An attacker could hide malicious activity from logs
  • Defenders may need to verify the integrity of their logs
  • Defenders should prioritize updating to a fixed version of Coraza

Technical summary

The Coraza WAF's Native audit-log format implementation is vulnerable to CRLF injection and log forgery attacks. This is due to the lack of escaping of `r` and `n` characters in the log output, which allows an attacker to inject fake log lines. The vulnerability affects the Native format's section structure, which is line-based and delimited by lines of the form `--<10-char-random-prefix>-<Part>--`. Any attacker-controlled bytes containing `n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. The JSON formatter (`formats_json.go`) and other

Defensive priority

Defenders should prioritize verifying the affected versions of Coraza in their environment and updating to version 3.8.0 or later. They should also review their log parsing and SIEM rules to ensure they are not vulnerable to log injection attacks.

Recommended defensive actions

  • Verify the version of Coraza in use and update to version 3.8.0 or later if necessary
  • Review log parsing and SIEM rules to ensure they are not vulnerable to log injection attacks
  • Monitor logs for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by the lack of escaping of `r` and `n` characters in the Native audit-log format implementation in Coraza. This allows an attacker to inject fake log lines by including `n` characters in the request body or header fields.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-41504 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-41504

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-41504 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41504

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.