CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107826

HIGHCVSS 7.5NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An un

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107826 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107826

HIGHCVSS 7.5NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An un

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]