CVE-2026-107835

Source
https://cve.org/CVERecord?id=CVE-2026-107835
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107835.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107835
Aliases
Published
2026-10-09T17:46:58Z
Modified
2026-10-10T10:30:47Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N CVSS Calculator
Summary
OWASP Coraza WAF: Cookie Parser Confusion
Details

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-436"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107835.json"
}
References

Affected packages

Git / github.com/corazawaf/coraza

Affected ranges

Type
GIT
Repo
https://github.com/corazawaf/coraza
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.8.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.0.0
v1.0.0-beta.1
v1.0.0-beta.2
v1.0.0-beta.3
v1.0.0-beta.4
v1.0.0-beta.5
v1.0.0-beta.6
v1.0.0-beta.7
v1.1.0
v1.2.0
v2.*
v2.0.0
v2.0.0-alpha.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-rc.1
v2.0.0-rc.2
v2.0.0-rc.3
v3.*
v3.0.0
v3.0.0-rc.1
v3.0.0-rc.2
v3.0.0-rc.3
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.1.0
v3.2.0
v3.2.1
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.4.0
v3.5.0
v3.6.0
v3.7.0
v3.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107835.json"