HIGH 7.2 GitHub

CVE-2026-41510

Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding

## Root Cause File: `internal/corazawaf/transaction.go`, lines 770–808 (since commit 2fd87b89, PR #812, 2023-06-14) ```go func (tx *Transaction) AddGetRequestArgument(key string, value string) { if tx.checkArgumentLimit(tx.variables.argsGet) { tx.debugLogger.Warn().Msg("skipping get request argument, over limit") return } tx.variables.argsGet.Add(key, value) } func (tx *Transaction) checkArgumentLimit(c *collections.NamedCollection) bool { return c.Len() >= tx.

Affected Products

References

Published: 2026-10-06 · Source: GitHub · Feed updated: 2026-10-06
This high severity vulnerability with a CVSS score of 7.2 was published on 2026-10-06 via GitHub. Affected: go/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.1.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.