Answer in brief
CVE-2026-107834 records a Medium severity (CVSS 5.3) vulnerability in OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor. The current sources do not mark it as known exploited. The current feed maps corazawaf/coraza (generic), github.com/corazawaf/coraza/v3 (go), github.com/corazawaf/coraza/v3 (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps corazawaf/coraza (generic), github.com/corazawaf/coraza/v3 (go), github.com/corazawaf/coraza/v3 (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| corazawaf/corazageneric | >=3.0.0 <3.8.0 | 3.8.0 |
| github.com/corazawaf/coraza/v3go | >=3.0.0,<3.8.0 | 3.8.0 |
| github.com/corazawaf/coraza/v3go | >=3.0.0 <3.8.0 | 3.8.0 |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.
Quoted source text, attributed separately from HOL analysis.