AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-41508.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 06, 2026

Disclosure summary

## Root Cause File: `internal/bodyprocessors/multipart.go` (since commit `3347961b`, PR #1453 *"feat: ignore unexpected EOF in MIME multipart request body processor"*, merged 2026-03-06, first shipped in `v3.4.0`). The multipart body processor treats `io.ErrUnexpectedEOF` as a benign condition. Three sites are affected; all mishandle the error the same way. ### File branch, filesystem-backed (lines 71–77) ```go sz, err := io.Copy(temp, p) if err != nil { if !errors.Is(err, io.ErrUnexpectedEOF) { v.MultipartStrictError().(*collections.Single).Set("1") return err } seenUnexpectedEOF = true //

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-r3rm-qphw-hh76

Open original source · Updated Oct 06, 2026

Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/corazawaf/coraza/v3>= 3.4.0,3.8.0
corazawaf/coraza releases · RSS-48cbe918174a8a005119b18c5ab8458dd77

Open original source · Updated Oct 02, 2026

v3.8.0

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2026-10-06T16:37:54-04:00
MODIFIED 2026-10-06T16:37:55-04:00
INGESTED 2026-10-08T12:05:11-04:00