CVE-2026-107833 | corazawaf Coraza up to 3.7.x JSON Body Processor json.go ProcessResponse ignoreJSONRecursionLimit allocation of resources
A vulnerability classified as problematic was found in corazawaf Coraza up to 3.7.x. The affected element is the function ProcessResponse of the file internal/bodyprocessors/json.go of the component JSON Body Processor. Such manipulation of the argument ignoreJSONRecursionLimit leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2026-107833. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More