OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rp9v-7xv3-r6g3 | Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0. | |
| Title | OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart body processor | |
| Weaknesses | CWE-400 CWE-772 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:41:07.802Z
Reserved: 2026-10-08T22:34:49.289Z
Link: CVE-2026-107834
No data.
Status : Received
Published: 2026-10-09T18:17:05.007
Modified: 2026-10-09T18:17:05.007
Link: CVE-2026-107834
No data.
OpenCVE Enrichment
Updated: 2026-10-09T18:30:11Z
Github GHSA