CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-41504: github.com/corazawaf/coraza/v3 >= 3.0.0, <= 3.7.0

CVE-2026-41504 affects github.com/corazawaf/coraza/v3. CVSS 3.1 base score 5.8 (GitHub Advisory Database). Affected range: >= 3.0.0, <= 3.7.0. Fixed version: 3.8.0.

Affected technology

github.com/corazawaf/coraza/v3 · >= 3.0.0, <= 3.7.0
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (GitHub Advisory Database, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The attacker can inject lines that look like genuine audit content. GitHub Advisory Database’s CVSS 3.1 assessment rates confidentiality and availability impact as none; integrity impact as low.

Published

Product
github.com/corazawaf/coraza/v3
CCR priority
23.2 /100 (P4)
CVSS 3.1
5.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N · GitHub Advisory Database
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-41504.html