{"id":"CVE-2026-107834","summary":"OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor","details":"OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.","aliases":["GHSA-rp9v-7xv3-r6g3"],"modified":"2026-10-11T02:46:45.045751448Z","published":"2026-10-09T17:41:07.802Z","database_specific":{"cwe_ids":["CWE-400","CWE-772"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107834.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107834.json"},{"type":"ADVISORY","url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107834"},{"type":"FIX","url":"https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/corazawaf/coraza","events":[{"introduced":"ad50864cfa00f5143fff7f6877847326fdc4b394"},{"fixed":"1bc39036e99c88e7de60cf8e6bb55ee4c311223c"},{"fixed":"19b86824f5e97eba72b289a81d5b3c1260292ff0"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.8.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v3.7.0","v3.6.0","v3.5.0","v3.4.0","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.1","v3.2.0","v3.1.0","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107834.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}