Repository Issue Activity (beta)

corazawaf/coraza

Current issue state, recent activity, and per-issue timelines from the indexed issue data.

Open Issues
57
New in 7 Days
0
Closed in 7 Days
0
Average Open Age
448 days
Stale 30+ Days
45
Stale 90+ Days
32
Last 2 Weeks
DateOpenedClosedCommentsEventsOpen Backlog
2026-09-2000001
2026-09-1900002
2026-09-18000057
2026-09-1700000
2026-09-1600000
2026-09-1500000
2026-09-1400000
2026-09-1300000
2026-09-1200000
2026-09-1100000
2026-09-1000000
2026-09-0900000
2026-09-0800000
2026-09-0700000
This Week

Opened: 0

Closed: 0

Comments: 0

Events: 0

Top Labels
bug (13)
enhancement (10)
fix (5)
security (5)
awaiting feedback (4)
documentation (4)
good first issue (3)
seclang (3)
Issue Explorer
IssueAuthorStateLabelsCommentsReactionsUpdated

#906 Dependency Dashboard

Opened 3 years ago
renovate[bot]
open - reopened
No labels
001 day ago

#1628 Large octet-stream request bodies are force-parsed into REQUEST_BODY/ARGS and transformed → memory blow-up (SecRequestBodyNoFilesLimit not enforced; forced URLENCODED vs RAW)

Opened 3 months ago
jptosso
open
No labels
112 days ago

#1681 Transformation cache misses on map-backed collections

Opened 1 month ago
M4tteoP
open
No labels
106 days ago

#1611 Coraza no longer 'best effort' parses JSON messages larger than configured SecRequestBodyLimit

Opened 5 months ago
Kortekaasy
open
No labels
2212 days ago

#1714 Implement RESPONSE_XML support

Opened 17 days ago
fzipi
open
No labels
0017 days ago

#1710 Fuzz tests #1331 failed

Opened 17 days ago
github-actions[bot]
closed - completed
No labels
1017 days ago

#1566 docs: investigate RESPONSE_CONTENT_LENGTH variable

Opened 6 months ago
M4tteoP
open
documentation
good first issue
1019 days ago

#1103 Native prometheus metrics

Opened 2 years ago
jptosso
open
No labels
9721 days ago

#1700 SecRuleUpdateTargetByTag silently does nothing: targets are added to a loop copy

Opened 22 days ago
fzipi
closed - completed
bug
seclang
0021 days ago

#1696 URLENCODED_ERROR is never set for the condition it documents; the decoder cannot detect it

Opened 23 days ago
fzipi
open
bug
seclang
0023 days ago

#1575 Add code blocks to documentation

Opened 6 months ago
fzipi
closed - completed
No labels
1123 days ago

#1686 Concurrent audit log writer: transaction ID is unsanitized in the audit record file path

Opened 27 days ago
fzipi
open
No labels
4024 days ago

#1104 Unsupported "accuracy" Action in SecRule Configuration

Opened 2 years ago
tigerwill90
closed - completed
No labels
5024 days ago

#1685 REQUEST_BODY is not populated when a body processor ran (XML/JSON), diverging from libmodsecurity v3

Opened 1 month ago
fzipi
open
No labels
2026 days ago

#1687 15 MULTIPART_* variables are declared but never populated, so rules referencing them silently never match

Opened 27 days ago
fzipi
open
bug
seclang
0027 days ago

#1670 normalise path and normalise path win too transformations return changed true for some cases even if the path not touched

Opened 2 months ago
HackingRepo
closed - completed
No labels
011 month ago

#1653 jsDecode doesn't decode ES2015+ \u{...} extended Unicode escapes

Opened 2 months ago
fzipi
closed - completed
bug
security
fix
111 month ago

#1675 `msg`/`logdata` macros are expanded on every rule evaluation, emitting spurious "key not found in collection" warnings

Opened 2 months ago
blotus
open
No labels
011 month ago

#1654 cssDecode writes a single raw byte for non-ASCII hex escapes instead of the codepoint's UTF-8 encoding

Opened 2 months ago
fzipi
closed - completed
bug
security
fix
112 months ago

#1656 normalisePathWin doesn't strip Windows' trailing dots/spaces or ADS suffixes

Opened 2 months ago
fzipi
closed - completed
bug
security
fix
102 months ago

#1651 base64DecodeExt truncates output at base64url '-'/'_', letting attacker-controlled tokens evade rules past that point

Opened 2 months ago
fzipi
closed - completed
bug
security
fix
012 months ago

#1655 compressWhitespace corrupts valid UTF-8 for common accented Latin-1-supplement characters

Opened 2 months ago
fzipi
closed - completed
bug
security
fix
112 months ago

#1674 cookieParser misinterepretaion of unicode cookie values

Opened 2 months ago
HackingRepo
open
No labels
002 months ago

#1666 Replace Comment transformation have some loopholes

Opened 2 months ago
HackingRepo
open
No labels
002 months ago

#1671 URI Decode uni discards high bits, leading to loopholes

Opened 2 months ago
HackingRepo
closed - completed
No labels
402 months ago

Rows per page:

1–25 of 140