CVE-2026-107833
Last modified
CVE-2026-107833 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero.
Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| corazawaf | coraza | >= 3.0.0, < 3.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107833?
How severe is CVE-2026-107833?
How do I fix CVE-2026-107833?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107826OWASP Coraza WAF is a golang modsecurity compatible web appl…7.5
- CVE-2026-107828Jivejdon through 5.0 contains an authentication bypass vulne…6.5
- CVE-2026-107829Jivejdon through 5.0 contains a weak password storage vulner…5.9
- CVE-2026-10783A security flaw has been discovered in gradio-app gradio 6.1…2.5
- CVE-2026-107830Jivejdon from commit e0306088 through commit ee67a65e lacks …5.3
- CVE-2026-107831Jivejdon through 5.0 contains a cross-site request forgery v…4.3
- CVE-2026-107834OWASP Coraza WAF is a golang modsecurity compatible web appl…5.3
- CVE-2026-107835OWASP Coraza WAF is a golang modsecurity compatible web appl…4
- CVE-2026-107836RIOT is an open-source microcontroller operating system desi…7.1
- CVE-2026-107837RIOT is an open-source microcontroller operating system desi…8.2
- CVE-2026-107838RIOT is an open-source microcontroller operating system desi…7.5
- CVE-2026-107839ageLANServer provides a cross-platform web server and launch…7.5
Are you affected by CVE-2026-107833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
