Skip to content
Threat Feed
high advisory updated

Coraza WAF Silent Argument Limit Bypass via Parameter Flooding

Coraza WAF silently drops parameters when the configured argument limit is reached, allowing attackers to evade security rules by flooding requests with filler parameters that force malicious payloads to be ignored by the WAF engine.

What's new

  • 1. added coverage for Coraza WAF (>= 3.0.0, < 3.8.1) Oct 8, 19:25 via ghsa

Coraza WAF (versions 3.0.0 through July 2026) contains a critical flaw in its argument parsing logic where the engine silently drops parameters once the SecArgumentsLimit (default 1000) is exceeded. This behavior occurs in AddGetRequestArgument, AddPostRequestArgument, and AddPathRequestArgument. Because the WAF engine fails to trigger an error, flag, or audit-log event when an argument is dropped, security rules inspecting ARGS, ARGS_GET, ARGS_POST, or ARGS_PATH proceed to evaluate an incomplete request without alerting the operator.

Furthermore, the parser for urlutil.ParseQuery iterates over maps in a non-deterministic order. Attackers can inflate the number of arguments in a request URI beyond the limit, forcing the WAF to randomly discard parameters, including potential exploit payloads. Additionally, the POST urlencoded body processor historically bypassed the argument limit entirely, and JSON processors lacked enforcement, creating both evasion and memory-exhaustion (DoS) surfaces. This vulnerability effectively nullifies OWASP Core Rule Set (CRS) protections against common attacks like SQLi, XSS, and RCE.

Attack Chain

  1. Attacker identifies a target application protected by an unpatched Coraza WAF instance.
  2. Attacker crafts a malicious payload (e.g., SQL injection) intended to trigger a blocked response.
  3. Attacker appends a large number of 'filler' parameters (e.g., 9999 dummy key-value pairs) to the URI query string or POST body.
  4. Coraza's parser processes the request and hits the SecArgumentsLimit threshold.
  5. The engine silently discards a subset of the arguments to maintain the limit, failing to update the transaction state or log an error.
  6. Due to Go's randomized map iteration, the malicious payload is dropped by the WAF before inspection in Phase 2.
  7. The WAF engine evaluates the remaining (sanitized) arguments against SecRule definitions.
  8. The WAF returns an HTTP 200 OK (or other benign status), allowing the malicious payload to reach the backend application.

Impact

Successful exploitation allows attackers to bypass any WAF rule targeting request arguments. Empirical testing demonstrates that flooding a request with 10,000 arguments yields a bypass rate of approximately 94% against standard detection rules. This facilitates the execution of SQL injection, cross-site scripting, and remote code execution attacks against the underlying application. Because the evasion is silent and occurs at the WAF engine level, incident responders may be unaware that attacks are reaching the backend. The vulnerability also poses a significant risk of memory-exhaustion-based Denial of Service (DoS) due to the lack of enforcement in the JSON and urlencoded body processors.

Recommendation

  1. Upgrade all Coraza WAF deployments to the latest version (post-2026-07-28) which enforces ArgumentLimit globally and provides the ARGUMENTS_LIMIT_REACHED transaction flag.
  2. If an immediate upgrade is not possible, implement compensating SecRule directives in the WAF configuration to block requests where the parameter count hits or exceeds the limit, ensuring that silent drops are converted into explicit rejections.
  3. Monitor web server logs for requests containing an unusually high volume of parameters as an indicator of potential parameter flooding attempts.

Immediate actions

Upgrade Coraza WAF to the patched version identified in the July 2026 fix

Infrastructure Operations 24h

Mitigations

Deploy compensating rules to block requests exceeding SecArgumentsLimit via ARGUMENTS_LIMIT_REACHED flag

immediate Security Engineering

Parameter flooding evasion