{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/coraza-waf--3.0.0--2026-07-28/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Coraza WAF (\u003e= 3.0.0, \u003c= 2026-07-28)","Coraza WAF (\u003e= 3.0.0, \u003c 3.8.1)"],"_cs_severities":["high"],"_cs_tags":["web-application-firewall","defense-evasion","parameter-flooding","security-bypass","denial-of-service","waf","coraza"],"_cs_type":"advisory","_cs_vendors":["Coraza"],"content_html":"\u003cp\u003eCoraza WAF (versions 3.0.0 through July 2026) contains a critical flaw in its argument parsing logic where the engine silently drops parameters once the \u003ccode\u003eSecArgumentsLimit\u003c/code\u003e (default 1000) is exceeded. This behavior occurs in \u003ccode\u003eAddGetRequestArgument\u003c/code\u003e, \u003ccode\u003eAddPostRequestArgument\u003c/code\u003e, and \u003ccode\u003eAddPathRequestArgument\u003c/code\u003e. Because the WAF engine fails to trigger an error, flag, or audit-log event when an argument is dropped, security rules inspecting \u003ccode\u003eARGS\u003c/code\u003e, \u003ccode\u003eARGS_GET\u003c/code\u003e, \u003ccode\u003eARGS_POST\u003c/code\u003e, or \u003ccode\u003eARGS_PATH\u003c/code\u003e proceed to evaluate an incomplete request without alerting the operator.\u003c/p\u003e\n\u003cp\u003eFurthermore, the parser for \u003ccode\u003eurlutil.ParseQuery\u003c/code\u003e iterates over maps in a non-deterministic order. Attackers can inflate the number of arguments in a request URI beyond the limit, forcing the WAF to randomly discard parameters, including potential exploit payloads. Additionally, the POST urlencoded body processor historically bypassed the argument limit entirely, and JSON processors lacked enforcement, creating both evasion and memory-exhaustion (DoS) surfaces. This vulnerability effectively nullifies OWASP Core Rule Set (CRS) protections against common attacks like SQLi, XSS, and RCE.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application protected by an unpatched Coraza WAF instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload (e.g., SQL injection) intended to trigger a blocked response.\u003c/li\u003e\n\u003cli\u003eAttacker appends a large number of 'filler' parameters (e.g., 9999 dummy key-value pairs) to the URI query string or POST body.\u003c/li\u003e\n\u003cli\u003eCoraza's parser processes the request and hits the \u003ccode\u003eSecArgumentsLimit\u003c/code\u003e threshold.\u003c/li\u003e\n\u003cli\u003eThe engine silently discards a subset of the arguments to maintain the limit, failing to update the transaction state or log an error.\u003c/li\u003e\n\u003cli\u003eDue to Go's randomized map iteration, the malicious payload is dropped by the WAF before inspection in Phase 2.\u003c/li\u003e\n\u003cli\u003eThe WAF engine evaluates the remaining (sanitized) arguments against \u003ccode\u003eSecRule\u003c/code\u003e definitions.\u003c/li\u003e\n\u003cli\u003eThe WAF returns an \u003ccode\u003eHTTP 200 OK\u003c/code\u003e (or other benign status), allowing the malicious payload to reach the backend application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass any WAF rule targeting request arguments. Empirical testing demonstrates that flooding a request with 10,000 arguments yields a bypass rate of approximately 94% against standard detection rules. This facilitates the execution of SQL injection, cross-site scripting, and remote code execution attacks against the underlying application. Because the evasion is silent and occurs at the WAF engine level, incident responders may be unaware that attacks are reaching the backend. The vulnerability also poses a significant risk of memory-exhaustion-based Denial of Service (DoS) due to the lack of enforcement in the JSON and urlencoded body processors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Coraza WAF deployments to the latest version (post-2026-07-28) which enforces \u003ccode\u003eArgumentLimit\u003c/code\u003e globally and provides the \u003ccode\u003eARGUMENTS_LIMIT_REACHED\u003c/code\u003e transaction flag.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, implement compensating \u003ccode\u003eSecRule\u003c/code\u003e directives in the WAF configuration to block requests where the parameter count hits or exceeds the limit, ensuring that silent drops are converted into explicit rejections.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for requests containing an unusually high volume of parameters as an indicator of potential parameter flooding attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T19:25:56Z","date_published":"2026-10-07T00:44:59Z","id":"https://feed.craftedsignal.io/briefs/2026-10-coraza-argument-bypass/","summary":"Coraza WAF silently drops parameters when the configured argument limit is reached, allowing attackers to evade security rules by flooding requests with filler parameters that force malicious payloads to be ignored by the WAF engine.","title":"Coraza WAF Silent Argument Limit Bypass via Parameter Flooding","url":"https://feed.craftedsignal.io/briefs/2026-10-coraza-argument-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Coraza WAF (\u003e= 3.0.0, \u003c= 2026-07-28)","version":"https://jsonfeed.org/version/1.1"}