MEDIUM 5.8 GitHub
CVE-2026-41508
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
## Root Cause
File: `internal/bodyprocessors/multipart.go` (since commit `3347961b`, PR #1453 *"feat: ignore unexpected EOF in MIME multipart request body processor"*, merged 2026-03-06, first shipped in `v3.4.0`).
The multipart body processor treats `io.ErrUnexpectedEOF` as a benign condition. Three sites are affected; all mishandle the error the same way.
### File branch, filesystem-backed (lines 71–77)
```go
sz, err := io.Copy(temp, p)
if err != nil {
if !errors.Is(err, io.ErrUnexpect
Affected Products
- go/github.com/corazawaf/coraza/v3 >= 3.4.0, <= 3.7.0
References
- https://github.com/advisories/GHSA-r3rm-qphw-hh76
- https://github.com/corazawaf/coraza/security/advisories/GHSA-r3rm-qphw-hh76
- https://github.com/corazawaf/coraza/commit/f94c81bec209f658120c418448d0590a549b71df
- https://github.com/corazawaf/coraza/releases/tag/v3.8.0
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-06 via GitHub. Affected: go/github.com/corazawaf/coraza/v3 >= 3.4.0, <= 3.7.0.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.