HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Antigravity CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
  4. CVE 2026 41504 coraza native audit log format allows crlf
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Servers
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Back to active CVEs
Medium · CVSS 5.8CVE-2026-41504GHSA-PRPW-WWV7-XJJR

Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fieldsCVE-2026-41504

Answer in brief

CVE-2026-41504 records a Medium severity (CVSS 5.8) vulnerability in Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields. The current sources do not mark it as known exploited. The current feed maps github.com/corazawaf/coraza/v3 (go). Check affected ranges and fixed versions before updating.

Analysis pending evidence review

HOL Guard separates source facts from reviewed analysis. See the methodology.

Published Oct 6, 2026Updated Oct 6, 2026Source checked Oct 7, 2026First seen by HOL Oct 6, 2026Material review Oct 6, 2026
Upstream Advisory

Key facts

Risk
Medium · CVSS 5.8
Exploitation
Not marked as known exploited
Affected software
1 mapped package or product
Fix availability
Available

Why this deserves its current priority

CVSS is 5.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.

Analysis status

Analysis pending evidence review

Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.

Affected scope and exposure questions

The current feed maps github.com/corazawaf/coraza/v3 (go). Check affected ranges and fixed versions before updating.

Mapped affected packages and fixed versions
PackageAffected rangeFixed version
github.com/corazawaf/coraza/v3go>=3.0.0,<=3.7.03.8.0

Recommended response

  1. 1Check inventory. Check lockfiles and deployed manifests for github.com/corazawaf/coraza/v3.
  2. 2Review the reported fix. Update github.com/corazawaf/coraza/v3 to 3.8.0 if you use the affected versions. Test the change in a non-production environment first.

Evidence timeline and material changes

  1. Published upstream

    Oct 6, 2026

    Evidence: source:ghsa:source_dates:source-dates:record
  2. Source modified

    Oct 6, 2026

    Evidence: source:ghsa:source_dates:source-dates:record
  3. First seen by HOL

    Oct 6, 2026

Sources and claim methodology

  • GitHub security advisorygithub.com
  • GitHub security advisorygithub.com
  • GitHub security advisorygithub.com
  • GitHub security advisorygithub.com
Upstream source description

## Root Cause File: `internal/auditlog/formats.go` — multiple sites write attacker-influenced bytes into the Native audit-log stream without escaping `\r` or `\n`: ```go // Part B — request headers (lines 72–80) for k, vv := range al.Transaction().Request().Headers() { for _, v := range vv { res.WriteByte('\n') res.WriteString(k) res.WriteString(": ") res.WriteString(v) // ← raw } } // Part C — request body (lines 85–86) if body := al.Transaction().Request().Body(); body != "" { res.WriteString(body) // ← raw res.WriteByte('\n') } // Part E — response body (lines 93–94) raw // Part F — response headers (lines 111–118) raw // Part H — error messages (line 125) raw // Part K — matched-rule raw data (line 151) raw ``` The Native format's section structure is line-based: sections are delimited by lines of the form `--<10-char-random-prefix>-<Part>--`, and line-based log parsers / SIEM rules rely on that structure. Any attacker-controlled bytes containing `\n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. The other two Native-format implementations in Coraza are not affected: the JSON formatter (`formats_json.go`) and the OCSF formatter both round-trip values through `json.Marshal`, which escapes `\r` and `\n`. ## Impact An attacker who can land bytes into any of the listed audit-log fields can inject arbitrary lines — including lines that visually resemble new log entries — into the audit log file of a defender running the default `SecAuditLogFormat Native` configuration. Realistic consequences: - **Forging entries to shift attribution.** An injected line such as `[client "9.9.9.9"] Coraza: Warning. ...` sits alongside genuine matches in Part H, and a human operator (or simple SIEM rule) reading the log cannot tell them apart. - **Confusing SIEM correlation.** Any ingestion pipeline that splits on `--...-[A-Z]--` boundaries or on `[client "..."]` patterns without validating the session prefix will treat the forged lines as separate records. - **Breaking log-parsing tooling.** Grep/awk pipelines, log tailers, and log-rotation tools with line-based assumptions can be poisoned with crafted binary sequences. - **Hiding genuine incidents.** An attacker who can also trigger a rule match on the same transaction (trivial — send any request that matches *any* audit-logged rule) can bury the real match under noise they control. The forged lines cannot trivially impersonate an entire *separate* session: the 10-char random prefix in the real boundaries (`boundaryPrefix := "--" + utils.RandomString(10) + "-"`, line 42) is not predictable from outside, and each transaction uses a fresh prefix. But the integrity of a *single* record is fully compromised, which is enough for the SIEM-confusion and attribution-shifting attacks. ## Proof of Concept Server with `coraza.conf-recommended`-style defaults: ```conf SecRuleEngine On SecAuditEngine On SecAuditLogParts ABCFHZ SecAuditLogType Serial SecAuditLog /tmp/audit.log SecAuditLogFormat Native SecRequestBodyAccess On SecRule REQUEST_METHOD "@rx ." \ "id:1001,phase:1,pass,log,auditlog,msg:'trigger'" ``` ### Body vector — reachable via stock `coraza/v3/http` + `net/http` Send an ordinary urlencoded POST whose body contains raw CRLF sequences and forged boundaries: ``` POST / HTTP/1.1 Content-Type: application/x-www-form-urlencoded evil=benign\r\n--coraza-forged-X--\r\nForgedLine: yes\r\n--coraza-forged-H--\r\n[client "9.9.9.9"] FAKE ATTACK ENTRY ``` Resulting audit.log: ``` --heLNtylvjY-C-- evil=benign --coraza-forged-X-- ForgedLine: yes --coraza-forged-H-- [client "9.9.9.9"] FAKE ATTACK ENTRY --heLNtylvjY-F-- ``` The forged `--coraza-forged-X--` / `--coraza-forged-H--` boundaries and the spoofed `[client "9.9.9.9"]` line are structurally indistinguishable from the surrounding genuine log content. No rule fires, no error is raised, the attack is invisible to the WAF. ### Header vector — reachable via non-net/http integrations only The same effect applies to Part B (request headers) and Part F (response headers) when a header value contains raw `\r\n`. Go's `net/http` rejects such headers at parse time (`400 Bad Request`), so the stock HTTP wrapper is safe from this path; the vector is reachable when Coraza is called with header values that were not validated by `net/http`: - `coraza-spoa` (HAProxy SPOP agent) forwards headers from HAProxy, which has more permissive validation. - `coraza-proxy-wasm` / Envoy WASM hosts forward header values from the upstream proxy. - Custom FFI/WASM hosts and any embedder calling `tx.AddRequestHeader(k, v)` with unvalidated bytes. Other raw-write sites (Part E response body, Part H error messages, Part K matched-rule data) share the same class of issue and should be fixed together. ## Mitigation Escape `\r` and `\n` at every raw-write site in `internal/auditlog/formats.go`. A single package-level helper is sufficient: ```go var logEscaper = strings.NewReplacer("\r", "\\r", "\n", "\\n") // Part B — header values: res.WriteString(logEscaper.Replace(v)) // Part F — header values: same // Part H — error messages: res.WriteString(logEscaper.Replace(alWithErrMsg.ErrorMessage())) // Part K — matched-rule raw data: res.WriteString(logEscaper.Replace(alEntry.Data().Raw())) ``` For Part C / Part E (bodies), the choice is policy-dependent: - **Escape inline** (`logEscaper.Replace(body)`): keeps the log human-readable for text bodies but loses fidelity for binary. - **Base64 / hex-encode** the whole part: binary-safe, matches the spirit of ModSecurity v2's binary-log handling, but less human-readable. Escaping is the minimum; base64 for bodies is the more conservative default and is a reasonable audit-log-default change. ### Additional defensive measure Consider lengthening the `boundaryPrefix` random suffix from 10 chars to ≥16 chars (line 42). This strictly raises the bar for attackers attempting to *fully* forge a separate-looking session (not just inject lines into the current one). Low-cost change; narrows future variants of this bug class. ## Affected versions The Native formatter has been present since `v3.0.0` (file existed at the first-release commit). All releases `>= 3.0.0, <= 3.7.0` are affected when `SecAuditLogFormat Native` is used with `SecAuditLogType Serial` or `SecAuditLogType Concurrent`. **Unaffected:** - Deployments using `SecAuditLogFormat JSON` (`formats_json.go` uses `json.Marshal` which escapes `\r\n`). - Deployments using OCSF output. - Deployments with `SecAuditEngine Off`. ## References - `internal/auditlog/formats.go` lines 42, 72–80 (Part B), 85–88 (Part C), 93–96 (Part E), 111–118 (Part F), 125 (Part H), 151 (Part K) - `coraza.conf-recommended` — default `SecAuditLogFormat Native`, `SecAuditLogParts ABIJDEFHZ` / `ABCFHZ` variants - CWE-117 — Improper Output Neutralization for Logs - CWE-93 — CRLF Injection

Quoted source text, attributed separately from HOL analysis.

Record context

Vulnerability class
Vulnerability
EPSS
Not reported
CWE IDs
CWE-93, CWE-117
Source
GitHub Security Advisories
Source checked
Oct 7, 2026
References
4 linked sources
Open source record