mediumCVSS 4Vulnerability

GHSA-x26q-wvhg-fh4m

## Root Cause File: `internal/corazawaf/transaction.go`, lines 834–866. ```go parsedURL, err := url.ParseRequestURI(uri) query := "" if err != nil { tx.variables.urlencodedError.Set(err.Error()) path = uri tx.variables.requestURI.Set(uri) /* tx.Variables.VARIABLE_URI_PARSE_ERROR.Set("1") posRawQuery := strings.Index(uri, "?") if posRawQuery != -1 { tx.ExtractArguments("GET", uri[posRawQuery+1:]) path = uri[:posRawQuery] query = uri[posRawQuery+1:] } else { path = uri } tx.Variables.RequestUri.Set(uri) */ } else { tx.ExtractGetArguments(parsedURL.RawQuery) // only path that populates ARGS_GET tx.variables.requestURI.Set(parsedURL.String()) path = parsedURL.Path query = parsedURL.RawQuery } ... tx.variables.queryString.Set(query) ``` When `url.ParseRequestURI(uri)` returns an error — which Go's stdlib does for any URI containing raw control bytes (`\x00`, `\n`, `\r`, `\t`, other `0x00–0x1F`, `0x7F`) — the error branch silently produces an empty `QUERY_STRING` and an empty `ARGS_GET` collection. The fallback logic that should split on `?` and populate the GET arguments from the raw tail is already present in the source as a commented-out block, referencing a `VARIABLE_URI_PARSE_ERROR` variable that was never wired up. Consequences on the error branch: - `ARGS_GET` / `ARGS_GET_NAMES` / `ARGS` (union) are **empty** — `ExtractGetArguments` is never called. - `QUERY_STRING` is **empty** (initial `query := ""` at line 835 persists through to `queryString.Set(query)` at line 866). - `REQUEST_FILENAME` / `REQUEST_BASENAME` contain the entire URI including any `?…` query suffix (because `path = uri` at line 838 bypasses the parse, and the subsequent `strings.LastIndexAny(path, "/\\")` runs over the raw URI). - `URLENCODED_ERROR` is set to the Go error message. That variable is *also* set by the urlencoded body processor on body-decode failu

Properties

severity
medium
summary
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
cvss_score
4
retrieved_at
2026-10-08T19:25:45+00:00
ghsa_published
2026-10-08T17:46:00Z
source_url
https://github.com/advisories/GHSA-x26q-wvhg-fh4m
ghsa_updated
2026-10-08T17:46:00Z
ghsa_id
GHSA-x26q-wvhg-fh4m
last_source
GitHub Advisory Database
cve_id
GHSA-x26q-wvhg-fh4m
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
signal_observed_at
2026-10-08T19:25:45+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]go/github.com/corazawaf/coraza/v3

AFFECTS (1)

→[Software]go/github.com/corazawaf/coraza/v3

HAS_WEAKNESS (2)

→[Weakness]Interpretation Conflict
→[Weakness]Improper Input Validation

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-x26q-wvhg-fh4m (CVSS 4) — Ninja Signal Threat Intelligence | Ninja Signal