SCA: security update for github.com/corazawaf/coraza/v3 (GHSA-x26q-wvhg-fh4m)

medium Tenable Cloud Security Plugin ID 473860

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until
3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining
the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty.
An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as
coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters
that the downstream integration may still process and allowing rules targeting those variables to be
bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such
malformed request targets before calling Coraza. This issue is fixed in version 3.8.0. (CVE-2026-107825)

Solution

Update the github.com/corazawaf/coraza/v3 library and its related packages to version 3.8.0 or later.

See Also

https://github.com/advisories/GHSA-x26q-wvhg-fh4m

Plugin Details

Severity: Medium

ID: 473860

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 10/8/2026

Updated: 10/9/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-107825

CVSS v3

Risk Factor: Medium

Base Score: 4

Temporal Score: 3.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-107825