mediumCVSS 5.8Vulnerability

GHSA-5gj4-9gm7-2fx2

### Summary Coraza's JSON body processor converts nested JSON properties into dot-separated `ARGS_POST` names without escaping dots contained in literal property names. Two distinct JSON properties can therefore collapse into the same Coraza variable An unauthenticated attacker can place a malicious value in a nested property and then overwrite only Coraza's representation with a harmless dotted property: ```json { "account": { "role": "1' OR '1'='1" }, "account.role": "safe" } ``` Coraza stores both properties as `ARGS_POST:json.account.role`; the later value `safe` replaces the SQL-injection value. Standard backend JSON parsers preserve the two distinct properties and expose the malicious nested value as `account.role`. This bypasses the complete current OWASP Core Rule Set (CRS) for the hidden value. In the supplied control-pair PoC, CRS v4.25 blocks the nested SQL-injection value with rule `949110`. Adding the dotted decoy makes the same attack pass with no interruption, while Go's standard JSON parser still returns the malicious nested value. ### Details The affected component is the JSON body processor in [`internal/bodyprocessors/json.go`](https://github.com/corazawaf/coraza/blob/db9850b2dd8992f97a8cefe08d0cb4edd966a04c/internal/bodyprocessors/json.go#L21-L48). `readJSON` creates a single `map[string]string` and begins every generated path with `json`: ```go func readJSON(s string, maxRecursion int) (map[string]string, error) { res := make(map[string]string) key := []byte("json") json := gjson.Parse(s) err := readItems(json, key, maxRecursion, res) // ... } ``` Source: [`internal/bodyprocessors/json.go`, lines 81-94](https://github.com/corazawaf/coraza/blob/db9850b2dd8992f97a8cefe08d0cb4edd966a04c/internal/bodyprocessors/json.go#L81-L94). For every object level, `readItems` appends a literal dot followed by the unescaped property name: ```go prevParentLength := len(objKey) objKey = append(objKey, '.') if key.Type ==

Properties

severity
medium
summary
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
cvss_score
5.8
retrieved_at
2026-10-08T19:25:45+00:00
ghsa_published
2026-10-08T17:45:31Z
source_url
https://github.com/advisories/GHSA-5gj4-9gm7-2fx2
ghsa_updated
2026-10-08T17:45:32Z
ghsa_id
GHSA-5gj4-9gm7-2fx2
last_source
GitHub Advisory Database
cve_id
GHSA-5gj4-9gm7-2fx2
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
signal_observed_at
2026-10-08T19:25:45+00:00
is_ghsa_only
true

Related Entities (5)

HAS_WEAKNESS (2)

→[Weakness]Improper Input Validation
→[Weakness]Interpretation Conflict

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]go/github.com/corazawaf/coraza/v3

AFFECTS (1)

→[Software]go/github.com/corazawaf/coraza/v3

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5gj4-9gm7-2fx2 (CVSS 5.8) — Ninja Signal Threat Intelligence | Ninja Signal