StackRadar

CVE-2026-107833

Medium

Advisory

Published 8 Oct 2026In the index since 10 Oct 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 18,090 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion

Carried by container images the latest versions of 8 of 18,090 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
github.com/corazawaf/coraza/v3golangv3.0.2, v3.0.4, v3.1.0, v3.2.1+2 more3.8.08
OSV records
GHSA-3c6w-j9xm-8h2h

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
github.com/corazawaf/coraza/v3@v3.6.0
3.8.0

Open the chart page →

1,505
casdoorcasdoorVerified publisher4.19.01 of 1See more

casdoor casdoor 4.19.0

1 of the 1 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
casbin/casdoor:4.19.01813811ddc1c
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0

Open the chart page →

907
csghubcsghubVerified publisher2.5.01 of 34See more

csghub csghub 2.5.0

1 of the 34 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0

Open the chart page →

64,659
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0

Open the chart page →

14,396
eg-edge-stackdatawire0.0.11 of 7See more

eg-edge-stack datawire 0.0.1

1 of the 7 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
github.com/corazawaf/coraza/v3@v3.0.2
3.8.0

Open the chart page →

85,761
easegresskubesphere-stable1.0.01 of 1See more

easegress kubesphere-stable 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
megaease/easegress:latestfad1c7452958
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0

Open the chart page →

1,871
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
github.com/corazawaf/coraza/v3@v3.0.4
3.8.0

Open the chart page →

3,092
wallarm-node-nextwallarmVerified publisher0.5.32 of 2See more

wallarm-node-next wallarm 0.5.3

2 of the 2 container images this version deploys carry CVE-2026-107833.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
github.com/corazawaf/coraza/v3@v3.1.0
3.8.0
wallarm/node-next:0.5.24314f3d2b918
github.com/corazawaf/coraza/v3@v3.2.1
3.8.0

Open the chart page →

3,676

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
casbin/casdoor:3.62.17729da148c61
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0
2
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
github.com/corazawaf/coraza/v3@v3.0.2
3.8.0
1
casbin/casdoor:4.19.01813811ddc1c
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0
1
datawire/aes:3.11.195ec30b3c732
github.com/corazawaf/coraza/v3@v3.0.4
3.8.0
1
megaease/easegress:latestfad1c7452958
github.com/corazawaf/coraza/v3@v3.3.3
3.8.0
1
wallarm/api-firewall:v0.9.64d45db0ff240
github.com/corazawaf/coraza/v3@v3.6.0
3.8.0
1
wallarm/node-helpers:5.0.2-1097cadc42336
github.com/corazawaf/coraza/v3@v3.1.0
3.8.0
1
wallarm/node-next:0.5.24314f3d2b918
github.com/corazawaf/coraza/v3@v3.2.1
3.8.0
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.