MEDIUM 5.8 GitHub

CVE-2026-41508

Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling

## Root Cause File: `internal/bodyprocessors/multipart.go` (since commit `3347961b`, PR #1453 *"feat: ignore unexpected EOF in MIME multipart request body processor"*, merged 2026-03-06, first shipped in `v3.4.0`). The multipart body processor treats `io.ErrUnexpectedEOF` as a benign condition. Three sites are affected; all mishandle the error the same way. ### File branch, filesystem-backed (lines 71–77) ```go sz, err := io.Copy(temp, p) if err != nil { if !errors.Is(err, io.ErrUnexpect

Affected Products

References

Published: 2026-10-06 · Source: GitHub · Feed updated: 2026-10-06
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-06 via GitHub. Affected: go/github.com/corazawaf/coraza/v3 >= 3.4.0, <= 3.7.0.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.