CVE-2025-29914: OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
URLs starting with //
are not parsed properly, and the request REQUEST_FILENAME
variable contains a wrong value, leading to potential rules bypass.
References
Detect and mitigate CVE-2025-29914 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →