# Coraza: the OWASP WAF engine that speaks ModSecurity's SecLang in Go

> Coraza is the OWASP Coraza Web Application Firewall, an Apache-2.0 Go library offering an enterprise-grade, high-performance WAF that supports ModSecurity SecLang rulesets and runs the OWASP Core Rule Set v4 with 100 percent compatibility. It is a library at heart with integrations for Caddy, Envoy, Traefik, HAProxy and nginx, build tags for advanced compilation modes, and FIPS 140-3 support detected at runtime, releasing v3.8.0 today.

**corazawaf/coraza** — OWASP Coraza WAF is a golang modsecurity compatible web application firewall library

- Repository: https://github.com/corazawaf/coraza
- Website: https://www.coraza.io
- Stars: 3,863 · Forks: 358
- Language: Go
- License: Apache-2.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/corazawaf-coraza

## Drop-in claims, qualified honestly

Coraza is an open source, enterprise-grade, high performance Web Application Firewall written in Go, supporting ModSecurity SecLang rulesets and 100 percent compatible with the OWASP Core Rule Set v4. The drop-in feature is worded with unusual care, Coraza is an alternative engine that has partial compatibility with the OWASP ModSecurity Engine and supports industry-standard SecLang rule sets, the phrase partial compatibility sitting right in the feature bullet rather than buried in a FAQ. That phrasing sets the migration contract, the common rules work, the CRS works fully, but a large existing ModSecurity configuration should be tested rather than assumed, and the project's own playground exists for exactly that rule testing. The simplicity bullet completes the feature set with a claim about the source itself, anyone is able to understand and modify the Coraza source code, and it is easy to extend Coraza with new functionality, a statement the extension points in the next bullet make concrete, audit loggers, persistence engines, operators and actions as the four plugin surfaces where custom functionality attaches.

## CRS v4 and what it catches

The security feature runs the OWASP Core Rule Set v4, formerly the Core Rule Set, to protect web applications from a wide range of attacks including the OWASP Top Ten with a minimum of false alerts. The enumerated categories read as the standard web threat list, SQL injection, cross site scripting, PHP and Java code injection, HTTPoxy, Shellshock, scripting, scanner and bot detection, and metadata and error leakages. The compatibility note is a warning in the same breath, older versions of the CRS are not compatible, so a deployment bringing its own rules must be on v4, and the engine's CRS support is backed by a dedicated coraza-coreruleset dependency in the module rather than an ad-hoc loader.

## A library first: WAF, transaction, phases

Coraza is a library at its core, usable for a Go program implementing a security middleware or integrating with existing applications and webservers, requiring a recent Go version per go.mod or a tinygo compiler, on Linux, Windows or Mac. The core usage example shows the shape:

```go
package main

import (
	"fmt"

	"github.com/corazawaf/coraza/v3"
)

func main() {
	// First we initialize our waf and our seclang parser
	waf, err := coraza.NewWAF(coraza.NewWAFConfig().
		WithDirectives(`SecRule REMOTE_ADDR "@rx .*" "id:1,phase:1,deny,status:403"`))
	// Now we parse our rules
	if err != nil {
		fmt.Println(err)
	}

	// Then we create a transaction and assign some variables
	tx := waf.NewTransaction()
	defer func() {
		tx.ProcessLogging()
		tx.Close()
	}()
	tx.ProcessConnection("127.0.0.1", 8080, "127.0.0.1", 12345)
```

NewWAF carries SecLang directives inline through NewWAFConfig, NewTransaction runs per request, and the code drives the phases explicitly, deferring ProcessLogging and Close. The example initializes with a one-line rule denying by remote address, calls ProcessConnection with the connection addresses, and proceeds into the request headers phase, the ModSecurity transaction lifecycle mapped onto Go function calls. The examples/http-server directory provides a working server to practice against.

## Six integrations, staged by stability

The integrations list carries explicit status labels. The Caddy reverse proxy plugin is stable but needs a maintainer. The proxy-wasm extension for proxies with proxy-wasm support such as Envoy is stable and still under development. The Traefik WASM extension is experimental and needs a maintainer. The HAProxy SPOA plugin is experimental. The Coraza C library for nginx and others is experimental. And RuiQi WAF, a third-party web management panel and enhanced traffic control for Coraza SPOA, is experimental. The labels are the honest deployment map, Caddy and Envoy today, the rest viable but seeking owners, and the needs-a-maintainer notes are the project asking publicly rather than silently letting integrations rot. The staging matters practically, a deployment that needs a management panel today pairs the HAProxy SPOA plugin with RuiQi, while a Caddy shop gets the stable plugin directly, and the maintainer-wanted notes tell contributors where the project most needs hands.

## Build tags that trade compatibility for speed

The build tags section is an advanced surface with no compatibility guarantees across minor versions. coraza.disabled_operators excludes operators from compilation to reduce binary size and startup overhead when overriding via plugins.RegisterOperator. coraza.rule.multiphase_evaluation evaluates rule variables in the phases they become ready rather than only the rule's phase. coraza.no_memoize disables the default memoization of regex and aho-corasick builders, which use a global cache across WAF instances, with the guidance that long-lived processes performing live reloads should release cached entries through WAF.Close via experimental.WAFCloser or opt out entirely. no_fs_access targets environments without filesystem access. Two rule behavior tags, case-sensitive ARGS keys aligned with RFC 3986 and the rx prefilter skipping full regexes when input cannot match, are flagged as becoming default in the next major version.

## FIPS 140-3, detected at runtime

Coraza supports running under Go's FIPS 140-3 mode, and the design detail is that detection happens at runtime so no build tag is required and default builds are unchanged. The restriction is specific, the t:md5 and t:sha1 transformations are unavailable whenever FIPS mode is on, under all of GODEBUG fips140 set to on, debug or only, and Coraza applies the restriction uniformly so behavior does not vary across FIPS modes. For regulated environments this is the difference between adopting the engine and not, the crypto transformations a rule set uses being exactly where FIPS boundaries bite, and the uniform enforcement means a compliance team verifies one behavior rather than per-build differences. The mage files beside them replace plain Makefiles for build orchestration, and the go.work file at the root marks multi-module local development, fitting a project whose integrations live in sibling repositories.

## A regulated codebase, and a retracted release

The repository's quality furniture includes a RATIONALE.md recording design decisions, a security policy, SonarQube properties, Codecov, CodeQL analysis and a regression workflow, mage files driving build tasks, renovate for dependency updates, and the AGENTS.md and CLAUDE.md marking AI-assisted contribution. The go.mod tells two stories, the analysis dependencies, libinjection-go for SQL injection detection, aho-corasick for pattern matching, gjson and binaryregexp, and a retracted v3.2.2 at the bottom, the formal marker of a release withdrawn. The project is active in the OWASP orbit with a Slack channel and playground, releases moving from v3.7.0 in April 2026 to v3.8.0 on 2026-09-30, published today, under Apache-2.0. The v3.8.0 release published today caps a year that also produced v3.6.0 and v3.7.0 in March and April, a cadence showing the engine under continuous rule and performance work rather than maintenance-only mode.

## Conclusion

Use Coraza when a Go service or proxy needs WAF protection with ModSecurity's rule language, since SecLang rulesets and CRS v4 run natively without the C engine, and the library shape lets you embed it in middleware rather than deploying a separate appliance. It offers partial ModSecurity compatibility, so audit exotic directives against the documentation before migrating. Before deploying, pick the integration matching your server, Caddy stable or the experimental nginx library, verify CRS v4 since older rule set versions are not compatible, and consider the multiphase evaluation and rx prefilter build tags for performance, knowing they lack cross-version guarantees.

## FAQ

### what is coraza waf?

Coraza is the OWASP Coraza Web Application Firewall, an open source, enterprise-grade, high performance WAF written in Go. It supports ModSecurity SecLang rulesets, is 100 percent compatible with the OWASP Core Rule Set v4, and works as a Go library with integrations for Caddy, Envoy, Traefik, HAProxy and nginx.

### How does Coraza compare to ModSecurity?

Coraza is an alternative engine with partial compatibility with the OWASP ModSecurity Engine, supporting the same industry-standard SecLang rule language. The common rules and the OWASP CRS v4 run fully, but the partial qualification means existing ModSecurity configurations should be tested, with the Coraza Playground available for rule testing.

### what does coraza mean in spanish?

Outside the software, coraza is a Spanish word, and the search results around it include unrelated businesses and products sharing the name. The software project's own name refers to the OWASP Coraza WAF, a Go web application firewall, whose documentation is at coraza.io.

## Sources

- [corazawaf/coraza on GitHub](https://github.com/corazawaf/coraza)
- [License: Apache-2.0](https://github.com/corazawaf/coraza/blob/main/LICENSE)
- [Project website](https://www.coraza.io)
- [README](https://github.com/corazawaf/coraza/blob/main/README.md)
- [Releases](https://github.com/corazawaf/coraza/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/corazawaf-coraza
