Coraza is a modular Web Application Firewall (WAF) engine that operates as a focused open-source project with a narrow product footprint centered on request filtering and protocol validation. The observed vulnerabilities cluster around resource-consumption issues and cases where classification remains pending, reflecting the parser and rate-limiting demands of WAF middleware. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coraza over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40586HIGH OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafte | Aug 25, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coraza.
Media articles that mention a CVE ID that affects a product developed by Coraza — matched by CVE ID, not by vendor name.