The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
GHSA-6gcq-wc29-5xf2: Coraza JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)
- Identifier
- GHSA-6gcq-wc29-5xf2
- Published
- Record updated
Summary
Coraza's JSON body processor (internal/bodyprocessors/json.go, readJSON) can crash the entire process with an unrecoverable fatal stack overflow. The flaw is that the argument-limit and byte-budget guards in readItems return before the recursion-depth check, so the unbounded gjson.Valid call then recurses over the full raw body. A request body well under the recommended SecRequestBodyLimit and the default SecArgumentsLimit triggers it, and the same readJSON path is reached on the response body via ProcessResponse.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.