<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Osama Ali on Cyshield Seclab</title><link>https://seclab.cyshield.com/authors/osama-ali/</link><description>Recent content in Osama Ali on Cyshield Seclab</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Cyshield.</copyright><lastBuildDate>Mon, 05 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://seclab.cyshield.com/authors/osama-ali/index.xml" rel="self" type="application/rss+xml"/><item><title>Coraza WAF Body Processors: SecArgumentsLimit Bypass Causes Memory-Exhaustion DoS</title><link>https://seclab.cyshield.com/advisories/cve-2026-41510/</link><pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2026-41510/</guid><description>A high severity vulnerability in Coraza WAF versions 3.0.0 through 3.8.0 allows remote, unauthenticated attackers to bypass SecArgumentsLimit when processing JSON or URL-encoded request bodies. Crafted requests can trigger excessive memory consumption, potentially causing process termination and denial of service. The issue is tracked as CVE-2026-41510 (CVSS 7.2) and is fixed in version 3.8.1.</description></item></channel></rss>