Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6gcq-wc29-5xf2 | Coraza JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1. | |
| Title | OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash) | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:55:14.751Z
Reserved: 2026-10-08T21:23:59.824Z
Link: CVE-2026-107826
Updated: 2026-10-09T17:54:52.263Z
Status : Received
Published: 2026-10-09T18:17:04.673
Modified: 2026-10-09T18:17:04.673
Link: CVE-2026-107826
No data.
OpenCVE Enrichment
Updated: 2026-10-09T19:00:16Z
Github GHSA