PatchSiren cyber security CVE debrief
CVE-2026-41510 corazawaf CVE debrief
The Coraza Web Application Firewall (WAF) is vulnerable to a silent argument drop at the ArgumentLimit, allowing an attacker to bypass ARGS-targeted rules via parameter flooding. This occurs because the `AddGetRequestArgument`, `AddPostRequestArgument`, and `AddPathRequestArgument` functions silently return once the per-collection argument count reaches the `WAF.ArgumentLimit` (default 1000). No error variable is set, no transaction flag is raised, and no rule can observe that a drop occurred.
- Vendor
- corazawaf
- Product
- Coraza Web Application Firewall (v3)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-06
Who should care
Defenders responsible for configuring and maintaining the Coraza WAF should be aware of this vulnerability and take steps to mitigate it. This includes verifying WAF configurations, updating to version 3.8.1 or later, and monitoring for potential parameter flooding attacks. Additionally, security teams and vulnerability management teams should prioritize addressing this vulnerability to prevent potential security breaches.
Why it matters
The Coraza WAF vulnerability CVE-2026-41510 allows an attacker to bypass ARGS-targeted rules via parameter flooding, potentially leading to security breaches. Defenders should prioritize verifying their Coraza WAF configurations and updating to version 3.8.1 or later to mitigate this vulnerability.
- Defenders need to verify their Coraza WAF configurations to ensure they are properly set up to handle argument limits.
- The vulnerability allows an attacker to bypass ARGS-targeted rules via parameter flooding, potentially leading to security breaches.
- Defenders should prioritize updating to version 3.8.1 or later to fix the vulnerability.
- The lack of error handling and transaction flagging when the argument limit is reached makes it difficult to detect and prevent attacks.
Technical summary
The Coraza WAF has a vulnerability in the `AddGetRequestArgument`, `AddPostRequestArgument`, and `AddPathRequestArgument` functions, which silently return once the per-collection argument count reaches the `WAF.ArgumentLimit`. This allows an attacker to bypass ARGS-targeted rules via parameter flooding. The vulnerability is caused by the lack of error handling and transaction flagging when the argument limit is reached. The `ExtractGetArguments` function iterates over the map returned by `urlutil.ParseQuery`, which can lead to silent argument drops. Defenders should prioritize verifying their Coraza WAF configurations and updating to version 3.8.1 or later to mitigate this vulnerability.
Defensive priority
Defenders should prioritize verifying their Coraza WAF configurations and updating to version 3.8.1 or later to mitigate this vulnerability.
Recommended defensive actions
- Verify Coraza WAF configurations to ensure they are properly set up to handle argument limits.
- Update to version 3.8.1 or later to fix the vulnerability.
- Monitor for potential parameter flooding attacks.
- Review and test WAF rules to ensure they are effective in detecting and preventing attacks.
- Perform vulnerability scanning to identify exposed systems.
- Implement additional monitoring for suspicious traffic patterns.
- Review incident response plans to ensure readiness.
Evidence notes
The vulnerability is caused by the lack of error handling and transaction flagging when the argument limit is reached. The `ExtractGetArguments` function iterates over the map returned by `urlutil.ParseQuery`, which can lead to silent argument drops.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41510 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41510
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41510 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41510
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-6r3q-mjv7-xr8m.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/security/advisories/GHSA-6r3q-mjv7-xr8m
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/146c2f79f39ad16f13787e7d67ad400f8d8cb9a3
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/commit/b98359bb7e7606c95100dcc7ad490d2d624e6dea
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/corazawaf/coraza/releases/tag/v3.8.1
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.