AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-104774.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

### Summary The `t:jsDecode` transformation in Coraza WAF contains an off-by-one error when parsing octal escape sequences. A backslash character was incorrectly included in the octal number buffer, causing `strconv.ParseInt` to fail for every octal escape sequence and return a null byte instead of the decoded value that would normally be returned. This will cause all JS-escaped payloads to be corrupted, thus leading to the bypassing of these WAF rules when WAF rules that rely on `jsDecode` for normalization are enabled. Therefore, a real-world attack scenario: an attacker could use JavaScript octal escape sequences (`\ooo`) to encode attack syntax. Although the WAF cannot decode these sequences correctly, the target backend (such as a browser or application) can parse them as expected. ### Details Vulnerable code: `internal/transformations/js_decode.go:64-70.` ```go case (i+1 < inputLen) && isodigit(input[i+1]): /* \OOO (only one byte, \000 - \377) */ buf := make([]byte, 3) j := 0 for (i+1+j < inputLen) && (j < 3) { buf[j] = input[i+j] // this should be `input[i+1+j]` j++ if !isodigit(input[i+j]) { break } } ``` This is because, when entering octal mode, the loop variable `i` poin

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-pc5q-qfxp-ggqv

Open original source · Updated Oct 08, 2026

Coraza: jsDecode Off-by-One in Octal Escape Handling Enables WAF Bypass

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/corazawaf/coraza/v3>= 3.0.0, < 3.8.03.8.0

Original records & references

PUBLISHED 2026-10-08T13:45:53-04:00
MODIFIED 2026-10-08T13:45:54-04:00
INGESTED 2026-10-10T20:25:13-04:00