V3: Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
Description
Coraza v3 has a vulnerability where it fails to inspect URL-encoded form bodies if the Content-Type header includes media-type parameters such as charset=UTF-8. This causes Coraza to skip parsing the request body, allowing attackers to bypass custom rules inspecting POST arguments. The issue affects versions from 3.0.4 up to but not including 3.8.1. The vulnerability is rated medium severity with a CVSS score of 5.8. A patch is available to address this issue.
CVSS v3.1
Score 5.8medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Coraza's request-body processor selection compares the entire Content-Type header value for exact equality, failing when parameters like charset are present (e.g., 'application/x-www-form-urlencoded; charset=UTF-8'). This causes the request body processor to remain unset, leading Coraza to evaluate phase 2 without parsing the body or setting error flags. Consequently, POST arguments are not inspected by Coraza rules, but the backend still receives and processes the full request body. This deterministic bypass allows an unauthenticated attacker to evade detection by custom rules targeting ARGS_POST or REQUEST_BODY. The issue affects Coraza versions >=3.0.4 and <3.8.1. The current OWASP CRS includes a fallback rule (901340) mitigating this bypass in unmodified configurations. A patch is available.
Potential Impact
An unauthenticated attacker can bypass Coraza's request body inspection for URL-encoded forms with Content-Type headers containing parameters, such as charset. This allows malicious POST data to reach the backend without triggering Coraza's configured rules, potentially enabling command injection or other attacks that rely on POST parameters. The backend processes the full request body normally, but Coraza's inspection is incomplete, reducing the effectiveness of protections relying on ARGS_POST or REQUEST_BODY variables.
Mitigation Recommendations
A patch is available for Coraza versions >=3.0.4 and <3.8.1 to fix this issue. Users should upgrade to a fixed version. Additionally, the current OWASP CRS includes rule 901340 which forces fallback inspection and mitigates this bypass path in unmodified configurations. No other specific actions are required if using the latest CRS and patched Coraza versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w253-m66g-rx24
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac80fb92cdf04f65639c2ac
Added to database: 10/08/2026, 21:48:41 UTC
Last enriched: 10/08/2026, 22:11:27 UTC
Last updated: 10/08/2026, 22:11:27 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.