Disclosure summary
## Root Cause File: `internal/auditlog/formats.go` — multiple sites write attacker-influenced bytes into the Native audit-log stream without escaping `\r` or `\n`: ```go // Part B — request headers (lines 72–80) for k, vv := range al.Transaction().Request().Headers() { for _, v := range vv { res.WriteByte('\n') res.WriteString(k) res.WriteString(": ") res.WriteString(v) // ← raw } } // Part C — request body (lines 85–86) if body := al.Transaction().Request().Body(); body != "" { res.WriteString(body) // ← raw res.WriteByte('\n') } // Part E — response body (lines 93–94) raw // Part F — response headers (lines 111–118) raw // Part H — error messages (line 125) raw // Part K — matched-rule raw data (line 151) raw ``` The Native format's section structure is line-based: sections are delimited by lines of the form `-----`, and line-based log parsers / SIEM rules rely on that structure. Any attacker-controlled bytes containing `\n` break the structural invariant and allow the attacker to inject lines that look like genuine audit content. The other two Native-format implementations in Coraza are not affected: the JSON formatter (`formats_json.go`) and the OCSF formatter both round-trip v
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-prpw-wwv7-xjjr
Open original source · Updated Oct 06, 2026
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/corazawaf/coraza/v3 | >= 3.0.0, | 3.8.0 |
corazawaf/coraza releases · RSS-48cbe918174a8a005119b18c5ab8458dd77
Open original source · Updated Oct 02, 2026
v3.8.0
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-06T16:37:27-04:00
MODIFIED 2026-10-06T16:37:30-04:00
INGESTED 2026-10-08T12:05:11-04:00