CVE-2025-29914: Corazawaf Coraza

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with //, coraza will set a wrong value in REQUEST_FILENAME. For example, if the URI //bar/uploads/foo.php?a=b is passed to coraza: , REQUEST_FILENAME will be set to /uploads/foo.php. This can lead to a rules bypass. This vulnerability is fixed in 3.3.3.

Affected products

  • Corazawaf Coraza: before 3.3.3 (fixed in 3.3.3)

Published 2025-03-20. Last modified 2026-06-17.