<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Coraza - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/coraza/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 00:44:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/coraza/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Coraza WAF Silent Argument Limit Bypass via Parameter Flooding</title><link>https://feed.craftedsignal.io/briefs/2026-10-coraza-argument-bypass/</link><pubDate>Wed, 07 Oct 2026 00:44:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-coraza-argument-bypass/</guid><description>Coraza WAF silently drops parameters when the configured argument limit is reached, allowing attackers to evade security rules by flooding requests with filler parameters that force malicious payloads to be ignored by the WAF engine.</description><content:encoded><![CDATA[<p>Coraza WAF (versions 3.0.0 through July 2026) contains a critical flaw in its argument parsing logic where the engine silently drops parameters once the <code>SecArgumentsLimit</code> (default 1000) is exceeded. This behavior occurs in <code>AddGetRequestArgument</code>, <code>AddPostRequestArgument</code>, and <code>AddPathRequestArgument</code>. Because the WAF engine fails to trigger an error, flag, or audit-log event when an argument is dropped, security rules inspecting <code>ARGS</code>, <code>ARGS_GET</code>, <code>ARGS_POST</code>, or <code>ARGS_PATH</code> proceed to evaluate an incomplete request without alerting the operator.</p>
<p>Furthermore, the parser for <code>urlutil.ParseQuery</code> iterates over maps in a non-deterministic order. Attackers can inflate the number of arguments in a request URI beyond the limit, forcing the WAF to randomly discard parameters, including potential exploit payloads. Additionally, the POST urlencoded body processor historically bypassed the argument limit entirely, and JSON processors lacked enforcement, creating both evasion and memory-exhaustion (DoS) surfaces. This vulnerability effectively nullifies OWASP Core Rule Set (CRS) protections against common attacks like SQLi, XSS, and RCE.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target application protected by an unpatched Coraza WAF instance.</li>
<li>Attacker crafts a malicious payload (e.g., SQL injection) intended to trigger a blocked response.</li>
<li>Attacker appends a large number of 'filler' parameters (e.g., 9999 dummy key-value pairs) to the URI query string or POST body.</li>
<li>Coraza's parser processes the request and hits the <code>SecArgumentsLimit</code> threshold.</li>
<li>The engine silently discards a subset of the arguments to maintain the limit, failing to update the transaction state or log an error.</li>
<li>Due to Go's randomized map iteration, the malicious payload is dropped by the WAF before inspection in Phase 2.</li>
<li>The WAF engine evaluates the remaining (sanitized) arguments against <code>SecRule</code> definitions.</li>
<li>The WAF returns an <code>HTTP 200 OK</code> (or other benign status), allowing the malicious payload to reach the backend application.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to bypass any WAF rule targeting request arguments. Empirical testing demonstrates that flooding a request with 10,000 arguments yields a bypass rate of approximately 94% against standard detection rules. This facilitates the execution of SQL injection, cross-site scripting, and remote code execution attacks against the underlying application. Because the evasion is silent and occurs at the WAF engine level, incident responders may be unaware that attacks are reaching the backend. The vulnerability also poses a significant risk of memory-exhaustion-based Denial of Service (DoS) due to the lack of enforcement in the JSON and urlencoded body processors.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all Coraza WAF deployments to the latest version (post-2026-07-28) which enforces <code>ArgumentLimit</code> globally and provides the <code>ARGUMENTS_LIMIT_REACHED</code> transaction flag.</li>
<li>If an immediate upgrade is not possible, implement compensating <code>SecRule</code> directives in the WAF configuration to block requests where the parameter count hits or exceeds the limit, ensuring that silent drops are converted into explicit rejections.</li>
<li>Monitor web server logs for requests containing an unusually high volume of parameters as an indicator of potential parameter flooding attempts.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-firewall</category><category>defense-evasion</category><category>parameter-flooding</category><category>security-bypass</category><category>denial-of-service</category><category>waf</category><category>coraza</category></item></channel></rss>