Skip to main content

V3: Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection

0
Medium
Published: 10/08/2026 (10/08/2026, 17:51:53 UTC)
Source: GCVE Database
Product: github.com/corazawaf/coraza/v3

Description

Coraza v3 has a vulnerability where it fails to inspect URL-encoded form bodies if the Content-Type header includes media-type parameters such as charset=UTF-8. This causes Coraza to skip parsing the request body, allowing attackers to bypass custom rules inspecting POST arguments. The issue affects versions from 3.0.4 up to but not including 3.8.1. The vulnerability is rated medium severity with a CVSS score of 5.8. A patch is available to address this issue.

CVSS v3.1

Score 5.8medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Affected software

Goghsa
github.com/corazawaf/coraza/v3
Affected versions
>=3.0.4 <3.8.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 22:11:27 UTC

Technical Analysis

Coraza's request-body processor selection compares the entire Content-Type header value for exact equality, failing when parameters like charset are present (e.g., 'application/x-www-form-urlencoded; charset=UTF-8'). This causes the request body processor to remain unset, leading Coraza to evaluate phase 2 without parsing the body or setting error flags. Consequently, POST arguments are not inspected by Coraza rules, but the backend still receives and processes the full request body. This deterministic bypass allows an unauthenticated attacker to evade detection by custom rules targeting ARGS_POST or REQUEST_BODY. The issue affects Coraza versions >=3.0.4 and <3.8.1. The current OWASP CRS includes a fallback rule (901340) mitigating this bypass in unmodified configurations. A patch is available.

Potential Impact

An unauthenticated attacker can bypass Coraza's request body inspection for URL-encoded forms with Content-Type headers containing parameters, such as charset. This allows malicious POST data to reach the backend without triggering Coraza's configured rules, potentially enabling command injection or other attacks that rely on POST parameters. The backend processes the full request body normally, but Coraza's inspection is incomplete, reducing the effectiveness of protections relying on ARGS_POST or REQUEST_BODY variables.

Mitigation Recommendations

A patch is available for Coraza versions >=3.0.4 and <3.8.1 to fix this issue. Users should upgrade to a fixed version. Additionally, the current OWASP CRS includes rule 901340 which forces fallback inspection and mitigates this bypass path in unmodified configurations. No other specific actions are required if using the latest CRS and patched Coraza versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-w253-m66g-rx24
Osv Schema Version
1.4.0
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac80fb92cdf04f65639c2ac

Added to database: 10/08/2026, 21:48:41 UTC

Last enriched: 10/08/2026, 22:11:27 UTC

Last updated: 10/08/2026, 22:11:27 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses