CVE-2026-104774
Published:October 08, 2026
Updated:October 09, 2026
The "t:jsDecode" transformation in Coraza WAF contains an off-by-one error when parsing octal escape sequences. A backslash character was incorrectly included in the octal number buffer, causing "strconv.ParseInt" to fail for every octal escape sequence and return a null byte instead of the decoded value that would normally be returned. This will cause all JS-escaped payloads to be corrupted, thus leading to the bypassing of these WAF rules when WAF rules that rely on "jsDecode" for normalization are enabled. Therefore, a real-world attack scenario: an attacker could use JavaScript octal escape sequences ("\ooo") to encode attack syntax. Although the WAF cannot decode these sequences correctly, the target backend (such as a browser or application) can parse them as expected.
Affected Packages
https://github.com/corazawaf/coraza.git (GITHUB):
Affected version(s) >=v1.0.0-beta.2 <v3.8.0Fix Suggestion:
Update to version v3.8.0github.com/corazawaf/coraza/v3 (GO):
Affected version(s) >=v3.0.0 <v3.8.0Fix Suggestion:
Update to version v3.8.0Related Resources (4)
Do you need more information?
Contact UsCVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
LOW
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.8
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE