github.com/corazawaf/coraza/v3
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
Activity
- Latest release
- Apr 06, 2026
- Total releases
- 20
- Cadence
- ~26 days
- Last 12 months
- 4
Reach
- Stars
- 3.7k
Details
- First release
- Mar 17, 2023
| Version | Released | |
|---|---|---|
v3.7.0
minor
|
v3.7.0
minor
Dependencies (14)
+ 6 more |
|
v3.6.0
minor
|
v3.6.0
minor
Dependencies (14)
+ 6 more |
|
v3.5.0
minor
|
v3.5.0
minor
Dependencies (14)
+ 6 more |
|
v3.4.0
minor
|
v3.4.0
minor
Dependencies (14)
+ 6 more |
|
v3.3.3
patch
|
v3.3.3
patch
Dependencies (13)
+ 5 more |
|
v3.3.2
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.3.2
patch
Dependencies (13)
+ 5 more |
|
v3.3.1
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.3.1
patch
Dependencies (13)
+ 5 more |
|
v3.3.0
minor
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.3.0
minor
Dependencies (13)
+ 5 more |
|
v3.2.2
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.2.2
patch
Dependencies (13)
+ 5 more |
|
v3.2.1
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.2.1
patch
Dependencies (10)
+ 2 more |
|
v3.2.0
minor
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.2.0
minor
Dependencies (10)
+ 2 more |
|
v3.1.0
minor
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.1.0
minor
Dependencies (10)
+ 2 more |
|
v3.0.4
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.0.4
patch
Dependencies (10)
+ 2 more |
|
v3.0.3
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.0.3
patch
Dependencies (10)
+ 2 more |
|
v3.0.2
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.0.2
patch
Dependencies (9)
+ 1 more |
|
v3.0.1
patch
1 CVE
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v3.0.1
patch
Dependencies (9)
+ 1 more |
|
v3.0.0
initial
2 CVEs
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40586
GO-2023-1874
GHSA-c2pj-v37r-2p6h
Jul 05, 2023
Denial of service in github.com/corazawaf/coraza/v2 and v3 Due to the misuse of log.Fatalf, Coraza may crash after receiving crafted requests from attackers. Fixed in
3.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v3.0.0
initial
Dependencies (8)
|
|
v3.0.0-rc.3
pre
2 CVEs
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40586
GO-2023-1874
GHSA-c2pj-v37r-2p6h
Jul 05, 2023
Denial of service in github.com/corazawaf/coraza/v2 and v3 Due to the misuse of log.Fatalf, Coraza may crash after receiving crafted requests from attackers. Fixed in
3.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v3.0.0-rc.3
pre
Dependencies (8)
|
|
v3.0.0-rc.2
pre
2 CVEs
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40586
GO-2023-1874
GHSA-c2pj-v37r-2p6h
Jul 05, 2023
Denial of service in github.com/corazawaf/coraza/v2 and v3 Due to the misuse of log.Fatalf, Coraza may crash after receiving crafted requests from attackers. Fixed in
3.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v3.0.0-rc.2
pre
Dependencies (8)
|
|
v3.0.0-rc.1
pre
2 CVEs
CVE-2025-29914
GO-2025-3537
GHSA-q9f5-625g-xm39
Mar 25, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza OWASP Coraza WAF has parser confusion which leads to wrong URI in Fixed in
3.3.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40586
GO-2023-1874
GHSA-c2pj-v37r-2p6h
Jul 05, 2023
Denial of service in github.com/corazawaf/coraza/v2 and v3 Due to the misuse of log.Fatalf, Coraza may crash after receiving crafted requests from attackers. Fixed in
3.0.1
References Updated May 20, 2024 · Source: OSV.dev |
v3.0.0-rc.1
pre
Dependencies (7)
|