V3: Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding (CVE-2026-41510)
Description
CVE-2026-41510 is a vulnerability in Coraza WAF v3 where the argument limit for request parameters is silently enforced, causing some parameters to be dropped without any error or alert. This allows attackers to bypass security rules targeting request arguments by flooding the request with many parameters, causing the malicious payload to be discarded and invisible to detection rules. The POST urlencoded body processor bypasses the argument limit entirely, creating an additional bypass and potential memory DoS risk. The issue is also present in ModSecurity v3 but partially mitigated by default configurations.
CVSS v3.1
Score 7.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Coraza WAF v3 enforces a per-collection argument limit (default 1000) by silently dropping additional GET, POST, or PATH request arguments once the limit is reached, without setting error flags or logging. Due to Go's randomized map iteration order, which arguments are dropped is non-deterministic, allowing attackers to flood requests with filler parameters to probabilistically evade ARGS-targeted SecRules. The POST urlencoded body processor does not enforce this limit at all, allowing unbounded ARGS_POST growth and bypass. This silent argument drop enables evasion of OWASP CRS rules for SQLi, XSS, RCE, and LFI. The vulnerability is also present in ModSecurity v3 but is partially mitigated by default recommended configurations. The issue affects Coraza versions >=3.0.0 and <3.8.1.
Potential Impact
Attackers can bypass any security rule inspecting ARGS, ARGS_GET, ARGS_NAMES, ARGS_GET_NAMES, or ARGS_PATH by sending requests with more arguments than the configured limit (default 1000). The probability of bypass increases with the number of extra arguments, reaching up to 94% bypass rate with 10,000 arguments. This results in evasion of critical detection rules for SQL injection, cross-site scripting, remote code execution, and local file inclusion. Additionally, the POST urlencoded processor bypasses the argument limit entirely, creating a potential memory denial-of-service vector. The silent nature of the drop means no audit logs or flags indicate the bypass, complicating detection and response.
Mitigation Recommendations
A patch is available for Coraza WAF v3 to address this issue. Operators should upgrade to a fixed version >=3.8.1. Until patched, monitoring for unusually large numbers of request arguments and applying external rate limiting or request size limits may help mitigate exploitation risk. The vendor advisory confirms a fix is available. No other vendor advisory content contradicts this. The POST urlencoded processor's bypass should also be addressed in the patch. Operators should review and apply the patch promptly to prevent evasion and potential memory DoS.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6r3q-mjv7-xr8m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-41510"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac56b1c2cdf04f656e1c0ab
Added to database: 10/06/2026, 21:41:48 UTC
Last enriched: 10/06/2026, 21:42:27 UTC
Last updated: 10/06/2026, 21:42:27 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.