Update Coraza and x/net, score requests CRS could not inspect, add .ojoignore #10

Merged
james merged 3 commits from dependency-fixes into main 2026-10-09 22:00:59 +00:00
Owner

Clears the 12 open findings from the OJO CI scan. Three commits.

1. Update Coraza to 3.8.1 and golang.org/x/net to 0.60.0

Finding Package Result
GHSA-6gcq-wc29-5xf2, JSON body processor stack overflow coraza 3.8.0 fixed in 3.8.1
CVE-2026-41510, arguments dropped at the argument limit coraza 3.8.0 fixed upstream; see commit 2
GHSA-w253-m66g-rx24, Content-Type parameters coraza 3.8.0 fixed in 3.8.1
GHSA-g4qm-m288-5cp9, cookie parser confusion coraza 3.8.0 fixed in 3.8.1
GHSA-5gj4-9gm7-2fx2, JSON key collision coraza 3.8.0 fixed in 3.8.1
GHSA-3wr7-993q-jrff, multipart filename* decoy coraza 3.8.0 fixed in 3.8.1
CVE-2026-97032, -78663, -78669, -78660, -78659, HTTP/2 x/net 0.58.0 fixed in 0.60.0

x/net is an indirect dependency and the binary links only its html packages. go mod tidy also moved x/sync to 0.23.0 and x/text to 0.42.0.

2. Score requests CRS could not inspect in full

Updating Coraza does not close CVE-2026-41510 for Centinela. Upstream's fix sets a limit-reached flag and relies on deny rules 200004 and 200005 in its recommended configuration. Centinela runs detection-only and reads the CRS anomaly score, so a deny never acts and those rules add no score.

Measured on 3.8.0 and 3.8.1 alike, at paranoia 3:

Request Score
Injection in the query string 60
The same after 1200 filler arguments 2
Injection in a form body 63
The same after 1200 filler arguments 5

Evaluate now reads the engine's own flags and adds one critical finding (5) for each of:

  • the argument limit reached (reported as rule 200004)
  • a request body that failed to parse (200002)
  • a multipart body that failed strict validation (200003)

Each appears in the rules field of the decision log and counts toward the grey gate, so the request reaches the model.

Still open: the request is scored, not refused. A padded request lands around 7 to 10, under any sensible hard block, and for a form body the model sees only the first CENTINELA_MAX_BODY bytes. Refusing requests over the argument limit outright is a separate decision.

3. Add .ojoignore

One entry: dockerfile-no-healthcheck on Dockerfile. The runtime image is distroless static nonroot, with no shell or HTTP client for a HEALTHCHECK to run; liveness and readiness are Kubernetes HTTP probes on /healthz.

Before merging: the entry's reason says the risk is accepted in Balam. That record had not been created when this was written. Create it first, or drop this commit.

Verification

  • make vet, make build and make test (race detector) pass.
  • CRS scores, matched rules, escalation and block outcomes on the 68-record eval set are identical before and after.
  • An ojo scan of this branch (vuln and misconfig scanners) reports no vulnerabilities; 1 issue before .ojoignore, 0 after.

Merging to main runs build-and-push, which tags and publishes the next patch version.

Clears the 12 open findings from the OJO CI scan. Three commits. ## 1. Update Coraza to 3.8.1 and golang.org/x/net to 0.60.0 | Finding | Package | Result | |---|---|---| | GHSA-6gcq-wc29-5xf2, JSON body processor stack overflow | coraza 3.8.0 | fixed in 3.8.1 | | CVE-2026-41510, arguments dropped at the argument limit | coraza 3.8.0 | fixed upstream; see commit 2 | | GHSA-w253-m66g-rx24, Content-Type parameters | coraza 3.8.0 | fixed in 3.8.1 | | GHSA-g4qm-m288-5cp9, cookie parser confusion | coraza 3.8.0 | fixed in 3.8.1 | | GHSA-5gj4-9gm7-2fx2, JSON key collision | coraza 3.8.0 | fixed in 3.8.1 | | GHSA-3wr7-993q-jrff, multipart filename* decoy | coraza 3.8.0 | fixed in 3.8.1 | | CVE-2026-97032, -78663, -78669, -78660, -78659, HTTP/2 | x/net 0.58.0 | fixed in 0.60.0 | x/net is an indirect dependency and the binary links only its html packages. go mod tidy also moved x/sync to 0.23.0 and x/text to 0.42.0. ## 2. Score requests CRS could not inspect in full Updating Coraza does not close CVE-2026-41510 for Centinela. Upstream's fix sets a limit-reached flag and relies on deny rules 200004 and 200005 in its recommended configuration. Centinela runs detection-only and reads the CRS anomaly score, so a deny never acts and those rules add no score. Measured on 3.8.0 and 3.8.1 alike, at paranoia 3: | Request | Score | |---|---| | Injection in the query string | 60 | | The same after 1200 filler arguments | 2 | | Injection in a form body | 63 | | The same after 1200 filler arguments | 5 | Evaluate now reads the engine's own flags and adds one critical finding (5) for each of: - the argument limit reached (reported as rule 200004) - a request body that failed to parse (200002) - a multipart body that failed strict validation (200003) Each appears in the rules field of the decision log and counts toward the grey gate, so the request reaches the model. **Still open:** the request is scored, not refused. A padded request lands around 7 to 10, under any sensible hard block, and for a form body the model sees only the first CENTINELA_MAX_BODY bytes. Refusing requests over the argument limit outright is a separate decision. ## 3. Add .ojoignore One entry: dockerfile-no-healthcheck on Dockerfile. The runtime image is distroless static nonroot, with no shell or HTTP client for a HEALTHCHECK to run; liveness and readiness are Kubernetes HTTP probes on /healthz. **Before merging:** the entry's reason says the risk is accepted in Balam. That record had not been created when this was written. Create it first, or drop this commit. ## Verification - make vet, make build and make test (race detector) pass. - CRS scores, matched rules, escalation and block outcomes on the 68-record eval set are identical before and after. - An ojo scan of this branch (vuln and misconfig scanners) reports no vulnerabilities; 1 issue before .ojoignore, 0 after. Merging to main runs build-and-push, which tags and publishes the next patch version.
Coraza 3.8.1 fixes a JSON body processor stack overflow
(GHSA-6gcq-wc29-5xf2) and several inspection bypasses: arguments dropped
at the argument limit (CVE-2026-41510), Content-Type handling
(GHSA-w253-m66g-rx24), cookie parsing (GHSA-g4qm-m288-5cp9), JSON key
collisions (GHSA-5gj4-9gm7-2fx2) and multipart filename*
(GHSA-3wr7-993q-jrff). x/net 0.60.0 fixes HTTP/2 issues; it is an
indirect dependency and only its html packages are linked.

CRS scores, matched rules and outcomes on the eval set are identical
before and after.
Coraza keeps at most SecArgumentsLimit (1000) arguments per source and
drops the rest. Its recommended configuration answers that with rules
200002 to 200005, which deny. Centinela runs detection-only and reads
the CRS anomaly score, so those rules never acted and carry no score: a
SQL injection that scores 60 scored 2 once 1200 filler arguments were
put in front of it, on Coraza 3.8.0 and 3.8.1 alike. Updating Coraza
does not close CVE-2026-41510 for Centinela by itself.

Evaluate now reads the engine's own flags and adds one critical finding
(5) for each of: the argument limit reached, a request body that failed
to parse, and a multipart body that failed strict validation. Each is
reported as a matched rule under Coraza's id for it, so it shows in the
decision log and reaches the model.

This makes the request visible and escalated; it does not refuse it.
Scores on the eval set are unchanged.
Add .ojoignore with the accepted HEALTHCHECK finding
All checks were successful
test / go (pull_request) Successful in 4m38s
security-scan / security-scan (pull_request) Successful in 3m52s
efc9e29170
The runtime image is distroless/static:nonroot, which has no shell or
HTTP client for a Dockerfile HEALTHCHECK to run. Liveness and readiness
are Kubernetes HTTP probes on /healthz.

Mirrors the risk acceptance kept in Balam, so the CI scan stops
reporting dockerfile-no-healthcheck.

🔎 ojo scan results

No findings.

<!-- ojo-scan-summary --> ### 🔎 ojo scan results No findings.
james merged commit bcf65e8f9c into main 2026-10-09 22:00:59 +00:00
james deleted branch dependency-fixes 2026-10-09 22:01:01 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/centinela!10
No description provided.