mediumCVSS 5.8Vulnerability

GHSA-w253-m66g-rx24

### Summary Coraza fails to inspect URL-encoded form bodies when their valid `Content-Type` contains a media-type parameter, for example: ```http Content-Type: application/x-www-form-urlencoded; charset=UTF-8 ``` An unauthenticated attacker can use this header to hide the complete form body from custom Coraza rules that inspect `ARGS_POST` or `REQUEST_BODY`, while the bundled Go HTTP middleware forwards the body and the backend parses it normally. This is a deterministic request-body inspection bypass. Suggested severity: **Medium**. Current OWASP CRS includes rule `901340`, which forces fallback inspection and mitigates this path; this report does not claim a bypass of an unmodified current CRS ruleset ### Details The affected component is request-body processor selection in [`internal/corazawaf/transaction.go`](https://github.com/corazawaf/coraza/blob/db9850b2dd8992f97a8cefe08d0cb4edd966a04c/internal/corazawaf/transaction.go#L371-L390). `Transaction.AddRequestHeader` compares the complete lowercased header value using exact equality: ```go case "content-type": val := strings.ToLower(value) if val == "application/x-www-form-urlencoded" { tx.variables.reqbodyProcessor.Set("URLENCODED") } else if strings.HasPrefix(val, "multipart/form-data") { tx.variables.reqbodyProcessor.Set("MULTIPART") } ``` Source: [`internal/corazawaf/transaction.go`, lines 383-390](https://github.com/corazawaf/coraza/blob/db9850b2dd8992f97a8cefe08d0cb4edd966a04c/internal/corazawaf/transaction.go#L383-L390). The media type of `application/x-www-form-urlencoded; charset=UTF-8` remains `application/x-www-form-urlencoded`; `charset` is a parameter. Because Coraza compares the entire header, the comparison fails and `REQBODY_PROCESSOR` remains empty. `ProcessRequestBody` treats the empty processor as success: ```go rbp = strings.ToLower(rbp) if rbp == "" { tx.WAF.Rules.Eval(types.PhaseRequestBody, tx) return tx.interruption, nil } ``` Source: [`i

Properties

severity
medium
summary
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
cvss_score
5.8
retrieved_at
2026-10-08T19:25:45+00:00
ghsa_published
2026-10-08T17:51:53Z
source_url
https://github.com/advisories/GHSA-w253-m66g-rx24
ghsa_updated
2026-10-08T17:51:54Z
ghsa_id
GHSA-w253-m66g-rx24
last_source
GitHub Advisory Database
cve_id
GHSA-w253-m66g-rx24
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
signal_observed_at
2026-10-08T19:25:45+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]go/github.com/corazawaf/coraza/v3

AFFECTS (1)

→[Software]go/github.com/corazawaf/coraza/v3

HAS_WEAKNESS (2)

→[Weakness]Interpretation Conflict
→[Weakness]Improper Input Validation

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-w253-m66g-rx24 (CVSS 5.8) — Ninja Signal Threat Intelligence | Ninja Signal