Vulnerability GO-2025-3537
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
March 25, 2025 at 07:38 PM UTC
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza
v1.0.0-beta.1 - v1.2.0
v1.0.0-beta.1 - v1.2.0
Summary
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza
Details
OWASP Coraza WAF has parser confusion which leads to wrong URI in REQUEST_FILENAME in github.com/corazawaf/coraza
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
5 hours ago
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
v3.0.0 - v3.8.0 GHSA-6r3q-mjv7-xr8m
v3.0.0 - v3.8.0 GHSA-6r3q-mjv7-xr8m
Medium Risk
5 hours ago
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
v3.4.0 - v3.7.0 GHSA-r3rm-qphw-hh76
v3.4.0 - v3.7.0 GHSA-r3rm-qphw-hh76
Medium Risk
5 hours ago
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
v3.0.0 - v3.7.0 GHSA-prpw-wwv7-xjjr
v3.0.0 - v3.7.0 GHSA-prpw-wwv7-xjjr
Medium Risk
1 year ago
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
v1.0.0-beta.1 - v1.2.0 GHSA-q9f5-625g-xm39
v1.0.0-beta.1 - v1.2.0 GHSA-q9f5-625g-xm39
Medium Risk
1 year ago
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
v1.0.0-beta.1 - v1.2.0 GHSA-q9f5-625g-xm39
v1.0.0-beta.1 - v1.2.0 GHSA-q9f5-625g-xm39
Impacted packages
Timeline
Published
1 year ago
March 25, 2025 at 07:38 PM UTC
Last Modified
7 months ago
March 03, 2026 at 04:56 AM UTC