CVE-2026-107826
Last modified
CVE-2026-107826 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body.
Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| corazawaf | coraza | >= 3.0.0, < 3.8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107826?
How severe is CVE-2026-107826?
How do I fix CVE-2026-107826?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107820x64dbg-MCP Server is a native Model Context Protocol (MCP) p…5.3
- CVE-2026-107821MariaDB server is a community developed fork of MySQL server…8
- CVE-2026-107822MariaDB server is a community developed fork of MySQL server…6.4
- CVE-2026-107823MariaDB server is a community developed fork of MySQL server…7.2
- CVE-2026-107824x64dbg-MCP Server is a native Model Context Protocol (MCP) p…9.3
- CVE-2026-107825OWASP Coraza WAF is a golang modsecurity compatible web appl…4
- CVE-2026-107828Jivejdon through 5.0 contains an authentication bypass vulne…6.5
- CVE-2026-107829Jivejdon through 5.0 contains a weak password storage vulner…5.9
- CVE-2026-10783A security flaw has been discovered in gradio-app gradio 6.1…2.5
- CVE-2026-107830Jivejdon from commit e0306088 through commit ee67a65e lacks …5.3
- CVE-2026-107831Jivejdon through 5.0 contains a cross-site request forgery v…4.3
- CVE-2026-107833OWASP Coraza WAF is a golang modsecurity compatible web appl…5.9
Are you affected by CVE-2026-107826?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
