PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41510 corazawaf CVE debrief

The Coraza Web Application Firewall (WAF) is vulnerable to a silent argument drop at the ArgumentLimit, allowing an attacker to bypass ARGS-targeted rules via parameter flooding. This occurs because the `AddGetRequestArgument`, `AddPostRequestArgument`, and `AddPathRequestArgument` functions silently return once the per-collection argument count reaches the `WAF.ArgumentLimit` (default 1000). No error variable is set, no transaction flag is raised, and no rule can observe that a drop occurred.

Vendor
corazawaf
Product
Coraza Web Application Firewall (v3)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-06
Advisory published
2026-10-06
Advisory updated
2026-10-06

Who should care

Defenders responsible for configuring and maintaining the Coraza WAF should be aware of this vulnerability and take steps to mitigate it. This includes verifying WAF configurations, updating to version 3.8.1 or later, and monitoring for potential parameter flooding attacks. Additionally, security teams and vulnerability management teams should prioritize addressing this vulnerability to prevent potential security breaches.

Why it matters

The Coraza WAF vulnerability CVE-2026-41510 allows an attacker to bypass ARGS-targeted rules via parameter flooding, potentially leading to security breaches. Defenders should prioritize verifying their Coraza WAF configurations and updating to version 3.8.1 or later to mitigate this vulnerability.

  • Defenders need to verify their Coraza WAF configurations to ensure they are properly set up to handle argument limits.
  • The vulnerability allows an attacker to bypass ARGS-targeted rules via parameter flooding, potentially leading to security breaches.
  • Defenders should prioritize updating to version 3.8.1 or later to fix the vulnerability.
  • The lack of error handling and transaction flagging when the argument limit is reached makes it difficult to detect and prevent attacks.

Technical summary

The Coraza WAF has a vulnerability in the `AddGetRequestArgument`, `AddPostRequestArgument`, and `AddPathRequestArgument` functions, which silently return once the per-collection argument count reaches the `WAF.ArgumentLimit`. This allows an attacker to bypass ARGS-targeted rules via parameter flooding. The vulnerability is caused by the lack of error handling and transaction flagging when the argument limit is reached. The `ExtractGetArguments` function iterates over the map returned by `urlutil.ParseQuery`, which can lead to silent argument drops. Defenders should prioritize verifying their Coraza WAF configurations and updating to version 3.8.1 or later to mitigate this vulnerability.

Defensive priority

Defenders should prioritize verifying their Coraza WAF configurations and updating to version 3.8.1 or later to mitigate this vulnerability.

Recommended defensive actions

  • Verify Coraza WAF configurations to ensure they are properly set up to handle argument limits.
  • Update to version 3.8.1 or later to fix the vulnerability.
  • Monitor for potential parameter flooding attacks.
  • Review and test WAF rules to ensure they are effective in detecting and preventing attacks.
  • Perform vulnerability scanning to identify exposed systems.
  • Implement additional monitoring for suspicious traffic patterns.
  • Review incident response plans to ensure readiness.

Evidence notes

The vulnerability is caused by the lack of error handling and transaction flagging when the argument limit is reached. The `ExtractGetArguments` function iterates over the map returned by `urlutil.ParseQuery`, which can lead to silent argument drops.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-41510 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-41510

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-41510 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41510

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-6r3q-mjv7-xr8m.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-6r3q-mjv7-xr8m

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/146c2f79f39ad16f13787e7d67ad400f8d8cb9a3

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/commit/b98359bb7e7606c95100dcc7ad490d2d624e6dea

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.1

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.