HIGH 7.2 GitHub
CVE-2026-41510
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
## Root Cause
File: `internal/corazawaf/transaction.go`, lines 770–808 (since commit 2fd87b89, PR #812, 2023-06-14)
```go
func (tx *Transaction) AddGetRequestArgument(key string, value string) {
if tx.checkArgumentLimit(tx.variables.argsGet) {
tx.debugLogger.Warn().Msg("skipping get request argument, over limit")
return
}
tx.variables.argsGet.Add(key, value)
}
func (tx *Transaction) checkArgumentLimit(c *collections.NamedCollection) bool {
return c.Len() >= tx.
Affected Products
- go/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.1
References
- https://github.com/advisories/GHSA-6r3q-mjv7-xr8m
- https://github.com/corazawaf/coraza/security/advisories/GHSA-6r3q-mjv7-xr8m
- https://github.com/corazawaf/coraza/commit/146c2f79f39ad16f13787e7d67ad400f8d8cb9a3
- https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f
This high severity vulnerability with a CVSS score of 7.2 was published on 2026-10-06 via GitHub. Affected: go/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.1.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.