PatchSiren

corazawaf CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review corazawaf CVE published 2026-10-06

CVE-2026-41510

The Coraza Web Application Firewall (WAF) is vulnerable to a silent argument drop at the ArgumentLimit, allowing an attacker to bypass ARGS-targeted rules via parameter flooding. This occurs because the `AddGetRequestArgument`, `AddPostRequestArgument`, and `AddPathRequestArgument` functions silently return once the per-collection argument count reaches the `WAF.ArgumentLimit` (default 1000). No error var [truncated]

Review corazawaf CVE published 2026-10-06

CVE-2026-41508

CVE-2026-41508 Coraza Truncated multipart body bypasses MULTIPART_STRICT_ERROR via silent io.ErrUnexpectedEOF handling. The vulnerability was introduced in version 3.4.0 and fixed in version 3.8.0. Affected deployments should prioritize verifying and upgrading to version 3.8.0 or later, assessing exposure, and monitoring for potential exploitation attempts. This issue allows truncated multipart bodies to [truncated]