CVE-2026-41504 | Coraza up to 3.7.0 Native Audit Log Formatter formats.go WriteString v/body crlf injection

SecurityVulns

A vulnerability was found in Coraza up to 3.7.0. It has been classified as critical. Affected is the function WriteString of the file internal/auditlog/formats.go of the component Native Audit Log Formatter. This manipulation of the argument v/body causes crlf injection.

This vulnerability appears as CVE-2026-41504. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More