VYPR

Coraza WAF

by Trustwave

CVEs (2)

  • CVE-2026-107833MedOct 9, 2026
    risk 0.31cvss 5.9epss —

    OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network…

  • CVE-2026-107835MedOct 9, 2026
    risk 0.19cvss 4.0epss —

    OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend…