OWASP Coraza WAF

APIyesOSS—FREEyesDOCS4/5
OC7.2#8 of 32
—Web—WindowsoutMacoutLinux—Android—iOS

Ranked in Web Application Firewall Software ·Free plan

About

OWASP Coraza WAF is an open-source firewall for protecting APIs and web applications. It supports ModSecurity SecLang rulesets and is compatible with the OWASP Core Rule Set, whose protections include SQL injection, cross-site scripting, code injection, HTTPoxy, Shellshock, and scanner or bot activity. Coraza can run as a sidecar, proxy, or library in Go, C++, and WebAssembly. Official connectors cover NGINX, Envoy, Caddy, Apache APISIX, proxy-wasm, HAProxy, Traefik, and libcoraza. Teams can extend it with audit loggers, persistence engines, operators, actions, and plugins; examples include GeoIP support and a package embedding the Core Rule Set with recommended configuration. The Quick Start requires Go 1.24 or later. It is available for API, Linux, macOS, and self-hosted use, with an open-source plan at 0.00 USD per free. The documentation points users to GitHub Discussions and the OWASP Slack community, and provides Coraza Playground for rule testing. Coraza v3 does not currently support persistent collections such as IP, SESSION, and RESOURCE.

Who it is for

Coraza suits teams seeking an open-source WAF for APIs or web applications that can fit into varied proxy and library deployments. Its connectors, extensibility points, and supported rule sets give teams options for integrating and tailoring it.

What is good

  • Compatible with the OWASP Core Rule Set
  • Runs as a sidecar, proxy, or library
  • Connectors cover several proxy platforms
  • Includes a sandbox for testing rules

What to know first

  • Requires Go 1.24 or later
  • Persistent collections are not supported in v3

Verdict

Coraza offers a free, extensible WAF with broad connector options and compatibility with established rule sets. Teams that depend on persistent collections such as IP, SESSION, or RESOURCE should account for the v3 limitation.

Compared on web application firewall software

Free plan
Yescoraza.io
Managed rule sets
Yescoraza.io
API protection
Yescoraza.io
Bot management
Yescoraza.io

Facts

Purpose
Coraza is an open-source Web Application Firewall for APIs and web applications.coraza.io · 4 Oct 2026
Rule compatibility
Coraza supports ModSecurity SecLang rulesets and is 100% compatible with the OWASP Core Rule Set.coraza.io · 4 Oct 2026
Threat coverage
The documentation says OWASP CRS protects against attacks including SQL injection, cross-site scripting, code injection, HTTPoxy, Shellshock, and scanner or bot activity.coraza.io · 4 Oct 2026
Deployment
The product page says Coraza can run as a sidecar, proxy, or library in Go, C++, and WebAssembly.coraza.io · 4 Oct 2026
Integrations
Official connectors are listed for NGINX, Envoy, Caddy, Apache APISIX, proxy-wasm, HAProxy, Traefik, and libcoraza.coraza.io · 4 Oct 2026
Extensibility
Coraza’s documentation describes extensions through audit loggers, persistence engines, operators, actions, and plugins.coraza.io · 4 Oct 2026
Plugin examples
Official plugins include GeoIP support and a package that embeds the OWASP Core Rule Set and recommended Coraza configuration.coraza.io · 4 Oct 2026
Platforms
The introduction lists Linux distributions and Mac as prerequisites and states that Windows is not yet supported.coraza.io · 4 Oct 2026
Runtime requirement
The Quick Start page lists Go 1.24+ as a requirement.coraza.io · 4 Oct 2026
Support and community
The documentation points users to GitHub Discussions and the OWASP Slack community (#coraza).coraza.io · 4 Oct 2026
Limit
The internals documentation says persistent collections such as IP, SESSION, and RESOURCE are currently not supported in Coraza v3.coraza.io · 4 Oct 2026
Security testing
The docs provide Coraza Playground as a sandbox web interface for testing rules.coraza.io · 4 Oct 2026

Company

Founded
2021coraza.io · 28 Sept 2026

Best OWASP Coraza WAF alternatives

See all 20

Where it ranks on Inferse

Sources