{"affectedProducts":[{"name":"Coraza WAF","vendor":"OWASP","versions":["versions 3.0.0 through 3.8.0"]}],"cveId":"CVE-2026-41510","cvssScore":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L","cwe":"CWE-770: Allocation of Resources Without Limits or Throttling","disclosureTimeline":[{"date":"2026-04-16","event":"Pre-existing advisory","note":"GHSA-6r3q-mjv7-xr8m was reported to the Coraza maintainers."},{"date":"2026-04-21","event":"CVE reserved","note":"CVE-2026-41510 was reserved for the pre-existing GHSA-6r3q-mjv7-xr8m advisory."},{"date":"2026-07-01","event":"Discovered","note":"The argument-limit bypass affecting the JSON and URL-encoded request-body processors was identified."},{"date":"2026-07-14","event":"Vendor notified","note":"GHSA-3ww9-vw83-9w5x was submitted to the Coraza maintainers with technical details and a proof of concept."},{"date":"2026-07-29","event":"Advisories merged","note":"The maintainers merged GHSA-3ww9-vw83-9w5x into the pre-existing GHSA-6r3q-mjv7-xr8m advisory and extended the existing fix to cover both findings."},{"date":"2026-10-02","event":"Public disclosure"}],"discoveredBy":["Osama Ali"],"lastUpdated":"2026-10-05T00:00:00Z","published":"2026-10-02T00:00:00Z","references":[{"label":"GitHub Security Advisory GHSA-6r3q-mjv7-xr8m","url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-6r3q-mjv7-xr8m"}],"severity":"high","status":"Published","summary":"A high severity vulnerability in Coraza WAF versions 3.0.0 through 3.8.0 allows remote, unauthenticated attackers to bypass SecArgumentsLimit when processing JSON or URL-encoded request bodies. Crafted requests can trigger excessive memory consumption, potentially causing process termination and denial of service. The issue is tracked as CVE-2026-41510 (CVSS 7.2) and is fixed in version 3.8.1.\n","title":"Coraza WAF Body Processors: SecArgumentsLimit Bypass Causes Memory-Exhaustion DoS","url":"https://seclab.cyshield.com/advisories/cve-2026-41510/"}