Vulnerability GO-2023-1874
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 years ago
July 05, 2023 at 05:30 PM UTC
Denial of service in github.com/corazawaf/coraza/v2 and v3
v2.0.0-alpha.1 - v2.0.1
v2.0.0-alpha.1 - v2.0.1
Summary
Denial of service in github.com/corazawaf/coraza/v2 and v3
Details
Due to the misuse of log.Fatalf, Coraza may crash after receiving crafted requests from attackers.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
5 hours ago
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
v3.0.0 - v3.8.0 GHSA-6r3q-mjv7-xr8m
v3.0.0 - v3.8.0 GHSA-6r3q-mjv7-xr8m
Medium Risk
5 hours ago
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
v3.4.0 - v3.7.0 GHSA-r3rm-qphw-hh76
v3.4.0 - v3.7.0 GHSA-r3rm-qphw-hh76
Medium Risk
5 hours ago
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
v3.0.0 - v3.7.0 GHSA-prpw-wwv7-xjjr
v3.0.0 - v3.7.0 GHSA-prpw-wwv7-xjjr
Unknown
1 year ago
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza
v3.0.0-rc.1 - v3.3.2 GO-2025-3537
v3.0.0-rc.1 - v3.3.2 GO-2025-3537
Unknown
1 year ago
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza
v3.0.0-rc.1 - v3.3.2 GO-2025-3537
v3.0.0-rc.1 - v3.3.2 GO-2025-3537
Impacted packages
Timeline
Published
3 years ago
July 05, 2023 at 05:30 PM UTC
Last Modified
2 years ago
May 20, 2024 at 04:03 PM UTC