Disclosure summary
## Root Cause File: `internal/bodyprocessors/multipart.go` (since commit `3347961b`, PR #1453 *"feat: ignore unexpected EOF in MIME multipart request body processor"*, merged 2026-03-06, first shipped in `v3.4.0`). The multipart body processor treats `io.ErrUnexpectedEOF` as a benign condition. Three sites are affected; all mishandle the error the same way. ### File branch, filesystem-backed (lines 71–77) ```go sz, err := io.Copy(temp, p) if err != nil { if !errors.Is(err, io.ErrUnexpectedEOF) { v.MultipartStrictError().(*collections.Single).Set("1") return err } seenUnexpectedEOF = true //
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-r3rm-qphw-hh76
Open original source · Updated Oct 06, 2026
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/corazawaf/coraza/v3 | >= 3.4.0, | 3.8.0 |
corazawaf/coraza releases · RSS-48cbe918174a8a005119b18c5ab8458dd77
Open original source · Updated Oct 02, 2026
v3.8.0
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-06T16:37:54-04:00
MODIFIED 2026-10-06T16:37:55-04:00
INGESTED 2026-10-08T12:05:11-04:00