OWASP Coraza Web Application Firewall

OWASP Coraza is a golang enterprise-grade Web Application Firewall framework that supports Modsecurity’s seclang language and is 100% compatible with OWASP Core Ruleset.

Enrich your web application’s security with powerful rules that comprehensively enforce good cybersecurity behavior.

OWASP Coraza can be imported as a library or used with one of our connectors like coraza-server (GRPC and SPOA), coraza-caddy (web server, reverse proxy), docker (using connector).

About OWASP Coraza Web Application Firewall

Project Leaders

Juan Pablotosso

Email

Felipe Zipitria

Email

Jose Carlos Chavez

Email

Project Information

Production Project
Classification
WAF
Language
Go
License
Apache License 2.0
Latest Version
3.7.0
Contributors
59
GitHub Stars
3868
Downloads
0
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP Coraza Web Application Firewall | OWASP Foundation