AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-41504.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 06, 2026

Disclosure summary

## Root Cause File: `internal/auditlog/formats.go` — multiple sites write attacker-influenced bytes into the Native audit-log stream without escaping `\r` or `\n`: ```go // Part B — request headers (lines 72–80) for k, vv := range al.Transaction().Request().Headers() { for _, v := range vv { res.WriteByte('\n') res.WriteString(k) res.WriteString(": ") res.WriteString(v) // ← raw } } // Part C — request body (lines 85–86) if body := al.Transaction().Request().Body(); body != "" { res.WriteString(body) // ← raw res.WriteByte('\n') } // Part E — response body (lines 93–94) raw // Part F — response headers (lines 111–118) raw // Part H — error messages (line 125) raw // Part K — matched-rule raw data (line 151) raw ``` The Native format's section structure is line-based: sections are delimited by lines of the form `-----`, and line-based log parsers / SIEM rules rely on that structure. Any attacker-controlled bytes containing `\n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. The other two Native-format implementations in Coraza are not affected: the JSON formatter (`formats_json.go`) and the OCSF formatter both round-trip v

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-prpw-wwv7-xjjr

Open original source · Updated Oct 06, 2026

Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/corazawaf/coraza/v3>= 3.0.0,3.8.0
corazawaf/coraza releases · RSS-48cbe918174a8a005119b18c5ab8458dd77

Open original source · Updated Oct 02, 2026

v3.8.0

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2026-10-06T16:37:27-04:00
MODIFIED 2026-10-06T16:37:30-04:00
INGESTED 2026-10-08T12:05:11-04:00