-
-
Notifications
You must be signed in to change notification settings - Fork 470
Pull requests: coreruleset/coreruleset
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix: Skip Checking Responses feature is broken
release:fix
release:important
#4807
opened Sep 18, 2026 by
azurit
Member
Loading…
1 of 12 tasks
feat: refactoring of response rules skipping
➖ False Negative - Evasion
release:remove-rules
Remove one or more rules
#4806
opened Sep 15, 2026 by
azurit
Member
Loading…
1 of 12 tasks
feat: add In this PR we introduce a new detection
ftp_ssl_connect to rule 933150
➖ False Negative - Evasion
release:new-detection
#4805
opened Sep 15, 2026 by
HackingRepo
Contributor
Loading…
chore: bump pinned coraza-crs caddy-alpine image digest
release:ignore
Ignore for changelog release
#4799
opened Sep 11, 2026 by
fzipi
Member
Loading…
fix(unix): substring false positives with
builtin command
backport:lts-4.25.2
➕ False Positive
🧙 regex-assembly
release:fix
🧪 testcase
#4791
opened Sep 8, 2026 by
EsadCetiner
Member
Loading…
5 of 12 tasks
feat(933100): add a regression test
release:ignore
Ignore for changelog release
🧪 testcase
#4786
opened Sep 8, 2026 by
touchweb-vincent
Contributor
Loading…
2 of 12 tasks
feat(913100): block user-agent header containing a literal In this PR we introduce a new detection
useragent value
release:new-detection
#4778
opened Sep 6, 2026 by
EsadCetiner
Member
Loading…
3 of 12 tasks
feat: allow application/*+json and AWS JSON content types by default
backport:lts-4.25.2
➕ False Positive
release:fix
#4775
opened Sep 3, 2026 by
fzipi
Member
Loading…
fix(920274): exclude authorization, from, signature-input, and sec-ch-ua-full-version-list headers
release:fix
#4760
opened Aug 12, 2026 by
EsadCetiner
Member
Loading…
2 of 12 tasks
fix(932238): substring false positive with
dnf and who
release:fix
#4759
opened Aug 12, 2026 by
EsadCetiner
Member
Loading…
6 of 12 tasks
fix(932120): enforce boundary to reduce substring false positives
release:fix
#4757
opened Aug 8, 2026 by
EsadCetiner
Member
Loading…
5 of 12 tasks
feat: update restricted files and file extensions
release:new-detection
In this PR we introduce a new detection
#4756
opened Aug 8, 2026 by
EsadCetiner
Member
Loading…
1 of 12 tasks
feat: detect spoofed user-agents escaping special characters
release:new-detection
In this PR we introduce a new detection
#4755
opened Aug 8, 2026 by
EsadCetiner
Member
Loading…
4 of 12 tasks
chore: attest release artifacts with build provenance
release:new-feature
This PR introduces a new feature
#4750
opened Aug 3, 2026 by
fzipi
Member
Loading…
feat(unix): update command list for no argument commands
release:new-detection
In this PR we introduce a new detection
#4737
opened Jul 25, 2026 by
EsadCetiner
Member
Loading…
2 of 12 tasks
fix: add t:urlDecodeUni to rules 921151 and 932190 (#3919)
⏳ awaiting feedback
CRS dev asked feedback
#4708
opened Jul 15, 2026 by
Manvikamboz
Loading…
feat(934210): detect JWT alg:none attack in Authorization header
#4663
opened Jun 11, 2026 by
S0obi
Contributor
Loading…
10 of 12 tasks
fix(rce): decode URL-encoded payloads in header RCE rules (#3504)
Stale
#4655
opened Jun 8, 2026 by
potato-20
Loading…
fix(921140): detect base64 encoded header injection payloads
Stale
#4654
opened Jun 8, 2026 by
Prateeksaini12
Contributor
Loading…
feat(921270): Excessive Cookie Count
#4651
opened Jun 3, 2026 by
touchweb-vincent
Contributor
Loading…
2 of 12 tasks
feat(921260): Excessive HTTP Request Header Count
Stale
#4650
opened Jun 3, 2026 by
touchweb-vincent
Contributor
Loading…
3 of 12 tasks
fix(932180): reduce false positive - common word not welcome on PL1
Stale
#4648
opened Jun 3, 2026 by
touchweb-vincent
Contributor
Loading…
1 of 12 tasks
fix(932180): enforce boundaries for high-risk false positives entries
release:fix
#4632
opened May 7, 2026 by
EsadCetiner
Member
Loading…
6 of 12 tasks
Previous Next
ProTip!
Updated in the last three days: updated:>2026-09-16.