go package github.com/corazawaf/coraza is vulnerable to denial of service
Published Aug 25, 2023
7.5
HIGHCVSS 3.1
EPSS 0.72%
Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.
Affected products
-
- Version < 3.0.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
github.com/corazawaf/coraza/v2
Go
Introduced 0 Fixed not fixedgithub.com/corazawaf/coraza/v3
Go
Introduced 0 Fixed 3.0.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/corazawaf/coraza/v2 | 0 | not fixed |
| Go | github.com/corazawaf/coraza/v3 | 0 | 3.0.1 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Oct 2, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.72% (0.00723) | 52.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.60% (0.00605) | 44.09th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.42% (0.00422) | 59.97th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00088) | 39.38th | v3 (v2023.03.01) |
| May 6, 2024 | 0.05% (0.00046) | 15.96th | v3 (v2023.03.01) |
| Sep 2, 2023 | 0.05% (0.00046) | 13.96th | v3 (v2023.03.01) |
| Aug 26, 2023 | 0.04% (0.00043) | 6.94th | v3 (v2023.03.01) |
References (10)
- https://github.com/advisories/GHSA-c2pj-v37r-2p6h Advisory
- https://github.com/corazawaf/coraza-caddy/issues/48
- https://github.com/corazawaf/coraza/blob/82157f85f24c6107667bf0f686b71a72aafdf8a5/internal/bodyprocessors/multipart.go#L26-L29
- https://github.com/corazawaf/coraza/commit/24af0c8cf4f10bab558740b595712be3b85493ec
- https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c x_refsource_MISCPatch
- https://github.com/corazawaf/coraza/commit/e1b119b83e12c64f0957e00e8cad45a1b5f012f8
- https://github.com/corazawaf/coraza/releases/tag/v3.0.1
- https://github.com/corazawaf/coraza/security/advisories/GHSA-c2pj-v37r-2p6h x_refsource_CONFIRMMitigationVendor Advisory
- https://github.com/golang/go/blob/a031f4ef83edc132d5f49382bfef491161de2476/src/log/log.go#L288-L291
- https://nvd.nist.gov/vuln/detail/CVE-2023-40586
Change history (0)
No recorded changes yet.