OWASP Coraza WAF
Ranked in Web Application Firewall Software ·Free plan
About
OWASP Coraza WAF is an open-source firewall for protecting APIs and web applications. It supports ModSecurity SecLang rulesets and is compatible with the OWASP Core Rule Set, whose protections include SQL injection, cross-site scripting, code injection, HTTPoxy, Shellshock, and scanner or bot activity. Coraza can run as a sidecar, proxy, or library in Go, C++, and WebAssembly. Official connectors cover NGINX, Envoy, Caddy, Apache APISIX, proxy-wasm, HAProxy, Traefik, and libcoraza. Teams can extend it with audit loggers, persistence engines, operators, actions, and plugins; examples include GeoIP support and a package embedding the Core Rule Set with recommended configuration. The Quick Start requires Go 1.24 or later. It is available for API, Linux, macOS, and self-hosted use, with an open-source plan at 0.00 USD per free. The documentation points users to GitHub Discussions and the OWASP Slack community, and provides Coraza Playground for rule testing. Coraza v3 does not currently support persistent collections such as IP, SESSION, and RESOURCE.
Who it is for
Coraza suits teams seeking an open-source WAF for APIs or web applications that can fit into varied proxy and library deployments. Its connectors, extensibility points, and supported rule sets give teams options for integrating and tailoring it.
What is good
- Compatible with the OWASP Core Rule Set
- Runs as a sidecar, proxy, or library
- Connectors cover several proxy platforms
- Includes a sandbox for testing rules
What to know first
- Requires Go 1.24 or later
- Persistent collections are not supported in v3
Verdict
Coraza offers a free, extensible WAF with broad connector options and compatibility with established rule sets. Teams that depend on persistent collections such as IP, SESSION, or RESOURCE should account for the v3 limitation.
Compared on web application firewall software
Facts
- Purpose
- Coraza is an open-source Web Application Firewall for APIs and web applications.coraza.io · 4 Oct 2026
- Rule compatibility
- Coraza supports ModSecurity SecLang rulesets and is 100% compatible with the OWASP Core Rule Set.coraza.io · 4 Oct 2026
- Threat coverage
- The documentation says OWASP CRS protects against attacks including SQL injection, cross-site scripting, code injection, HTTPoxy, Shellshock, and scanner or bot activity.coraza.io · 4 Oct 2026
- Deployment
- The product page says Coraza can run as a sidecar, proxy, or library in Go, C++, and WebAssembly.coraza.io · 4 Oct 2026
- Integrations
- Official connectors are listed for NGINX, Envoy, Caddy, Apache APISIX, proxy-wasm, HAProxy, Traefik, and libcoraza.coraza.io · 4 Oct 2026
- Extensibility
- Coraza’s documentation describes extensions through audit loggers, persistence engines, operators, actions, and plugins.coraza.io · 4 Oct 2026
- Plugin examples
- Official plugins include GeoIP support and a package that embeds the OWASP Core Rule Set and recommended Coraza configuration.coraza.io · 4 Oct 2026
- Platforms
- The introduction lists Linux distributions and Mac as prerequisites and states that Windows is not yet supported.coraza.io · 4 Oct 2026
- Runtime requirement
- The Quick Start page lists Go 1.24+ as a requirement.coraza.io · 4 Oct 2026
- Support and community
- The documentation points users to GitHub Discussions and the OWASP Slack community (#coraza).coraza.io · 4 Oct 2026
- Limit
- The internals documentation says persistent collections such as IP, SESSION, and RESOURCE are currently not supported in Coraza v3.coraza.io · 4 Oct 2026
- Security testing
- The docs provide Coraza Playground as a sandbox web interface for testing rules.coraza.io · 4 Oct 2026
Company
- Founded
- 2021coraza.io · 28 Sept 2026
Best OWASP Coraza WAF alternatives
See all 20Where it ranks on Inferse
Sources
- coraza.io· checked 4 Oct 2026
- coraza.io/docs/tutorials/introduction/· checked 4 Oct 2026
- coraza.io/connectors/· checked 4 Oct 2026
- coraza.io/plugins/· checked 4 Oct 2026
- coraza.io/docs/tutorials/quick-start/· checked 4 Oct 2026
- coraza.io/docs/reference/internals/· checked 4 Oct 2026




