VDB
GO-2025-3537
GO-2025-3537
PUBLISHED
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | corazawaf/coraza/v2 | 0, 0 |
| github.com | jptosso/coraza-waf | 0, 0 |
| github.com | corazawaf/coraza | 0, 0 |
| github.com | corazawaf/coraza/v3 | 0, 0 |
Timeline
- Mar 25, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory