-
-
Notifications
You must be signed in to change notification settings - Fork 468
Pull requests: coreruleset/coreruleset
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix(920274): exclude authorization, from, signature-input, and sec-ch-ua-full-version-list headers
release:fix
#4760
opened Aug 12, 2026 by
EsadCetiner
Member
Loading…
2 of 12 tasks
fix(932238): substring false positive with
dnf and who
release:fix
#4759
opened Aug 12, 2026 by
EsadCetiner
Member
Loading…
6 of 12 tasks
fix(932120): enforce boundary to reduce substring false positives
release:fix
#4757
opened Aug 8, 2026 by
EsadCetiner
Member
Loading…
5 of 12 tasks
feat: update restricted files and file extensions
release:new-detection
In this PR we introduce a new detection
#4756
opened Aug 8, 2026 by
EsadCetiner
Member
Loading…
1 of 12 tasks
feat: detect spoofed user-agents escaping special characters
release:new-detection
In this PR we introduce a new detection
#4755
opened Aug 8, 2026 by
EsadCetiner
Member
Loading…
4 of 12 tasks
fix(956100): FP with keyword 'EOFError' inside RESPONSE_BODY
#4752
opened Aug 5, 2026 by
azurit
Member
Loading…
2 of 12 tasks
feat: attest release artifacts with build provenance
#4750
opened Aug 3, 2026 by
fzipi
Member
Loading…
fix(951230): FP with too broad regex for RESPONSE_BODY
#4747
opened Aug 3, 2026 by
azurit
Member
Loading…
1 of 12 tasks
chore: showcase new quantitative workflow output (do not merge)
⚠️ do not merge
Additional work or discussion is needed despite passing tests
#4740
opened Jul 25, 2026 by
fzipi
Member
Loading…
feat(unix): update command list for no argument commands
release:new-detection
In this PR we introduce a new detection
#4737
opened Jul 25, 2026 by
EsadCetiner
Member
Loading…
2 of 12 tasks
feat(unix): detect common selinux command usage
release:new-detection
In this PR we introduce a new detection
#4724
opened Jul 19, 2026 by
EsadCetiner
Member
Loading…
2 of 12 tasks
fix: add t:urlDecodeUni to rules 921151 and 932190 (#3919)
⏳ awaiting feedback
CRS dev asked feedback
#4708
opened Jul 15, 2026 by
Manvikamboz
Loading…
feat(934210): detect JWT alg:none attack in Authorization header
#4663
opened Jun 11, 2026 by
S0obi
Contributor
Loading…
10 of 12 tasks
fix(rce): decode URL-encoded payloads in header RCE rules (#3504)
#4655
opened Jun 8, 2026 by
potato-20
Loading…
fix(921140): detect base64 encoded header injection payloads
#4654
opened Jun 8, 2026 by
Prateeksaini12
Contributor
Loading…
feat(921270): Excessive Cookie Count
#4651
opened Jun 3, 2026 by
touchweb-vincent
Contributor
Loading…
2 of 12 tasks
feat(921260): Excessive HTTP Request Header Count
#4650
opened Jun 3, 2026 by
touchweb-vincent
Contributor
Loading…
3 of 12 tasks
fix(932180): reduce false positive - common word not welcome on PL1
#4648
opened Jun 3, 2026 by
touchweb-vincent
Contributor
Loading…
1 of 12 tasks
fix(932180): enforce boundaries for high-risk false positives entries
release:fix
#4632
opened May 7, 2026 by
EsadCetiner
Member
Loading…
6 of 12 tasks
test: add containerized default go-ftw tests to docker compose file
⏳ awaiting feedback
CRS dev asked feedback
#4627
opened May 1, 2026 by
studersi
Contributor
Loading…
6 of 12 tasks
fix(932130): detect ANSI-C quoting hex-encoded commands
#4598
opened Mar 30, 2026 by
zoutjebot
Contributor
Loading…
fix(942190,942230): detect SQLite == and GLOB, PostgreSQL ARRAY @>
#4597
opened Mar 30, 2026 by
zoutjebot
Contributor
Loading…
fix(932270): require boundary before tilde expansion patterns
release:fix
#4596
opened Mar 30, 2026 by
zoutjebot
Contributor
Loading…
Previous Next
ProTip!
Adding no:label will show everything without a label.