Due to the misuse of log.Fatalf, Coraza may crash after receiving crafted requests from attackers.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-1874" }
{ "imports": [ { "path": "github.com/corazawaf/coraza/v2/bodyprocessors", "symbols": [ "multipartBodyProcessor.Read" ] } ] }
"https://vuln.go.dev/ID/GO-2023-1874.json"
{ "imports": [ { "path": "github.com/corazawaf/coraza/v3/internal/bodyprocessors", "symbols": [ "multipartBodyProcessor.ProcessRequest" ] } ] }