Executive brief
CrowdSec, a security tool used to protect servers from malicious IP addresses and cyberattacks, contained a flaw in its Web Application Firewall (WAF) component. This flaw allowed attackers to bypass security rules by using specific web request formats that the system failed to inspect properly. As a result, malicious traffic containing harmful data could reach protected applications without being blocked.
Technical details
A vulnerability in CrowdSec's AppSec component (specifically in `pkg/appsec/request.go`) caused the WAF to skip inspection of request bodies under certain conditions. The function `NewParsedRequestFromRequest` incorrectly allocated the request body buffer based on the `Content-Length` header; if this header was missing or zero (common in HTTP/1.1 chunked encoding or HTTP/2), the buffer remained empty. Consequently, security rules targeting `REQUEST_BODY`, `BODY_ARGS`, `ARGS_POST`, `JSON`, or `XML` were not applied to the actual payload. Attackers could exploit this to deliver malicious payloads that bypass WAF filtering. The issue is resolved in version 1.7.8 by properly enforcing body size limitations and handling varied transfer encodings.
Affected products
- CrowdSecurity CrowdSec >= 1.5.0, < 1.7.8
Timeline
- 2026-03-05: other: Initial pull request for fix opened
- 2026-07-16: disclosed: CVE published
- 2026-07-16: patched: Version 1.7.8 released
References
- https://github.com/crowdsecurity/crowdsec/commit/3d5c4d9b127091e9063b9b5eb785372a599a4435
- https://github.com/crowdsecurity/crowdsec/commit/57a793548671e6bbd2cde5562fe87b856ec9c642
- https://github.com/crowdsecurity/crowdsec/pull/4355
- https://github.com/crowdsecurity/crowdsec/releases/tag/v1.7.8
- https://github.com/crowdsecurity/crowdsec/security/advisories/GHSA-rw47-hm26-6wr7