github fabriziosalmi/patterns 2026-10-01-crs-v4.29.0-2
WAF rules 2026-10-01-crs-v4.29.0-2

3 hours ago

Patterns build · 2026-10-01

OWASP Core Rule Set coreruleset/coreruleset@v4.29.0 converted into native WAF rules for four web servers. Generated automatically; no manual edits.

Coverage: 749 patterns across 22 categories — SQLi, XSS, RCE, LFI, RFI, plus generic anomaly and protocol-violation rules.

What changed since the previous release

No rule changed since the previous release (CRS v4.29.0).

The whole of it, per rule and per target, is in changes.json, attached to this release.

Backends

Backend Format Bots Archive Size
Nginx map + if 1868 nginx_waf.zip 52K
Apache ModSecurity 1868 apache_waf.zip 68K
Traefik Middleware TOML 1868 traefik_waf.zip 20K
HAProxy Pattern files 1868 haproxy_waf.zip 60K

Quick install

curl -LO https://github.com/fabriziosalmi/patterns/releases/download/2026-10-01-crs-v4.29.0-2/nginx_waf.zip
unzip nginx_waf.zip -d /etc/nginx/waf_patterns

Integration guides → Nginx · Apache · Traefik · HAProxy

What each target does with each rule

Of the 749 records in the CRS v4.29.0 intermediate representation, what each target does:

Target Full Approximate Unsound Dropped
Nginx 11 159 0 579
Apache (ModSecurity) 7 159 0 583
Traefik 0 3 0 746
HAProxy 6 160 0 583

Why a record is dropped, by the first reason the backend found:

Reason Nginx Apache (ModSecurity) Traefik HAProxy
an operator the backend cannot express 292 319 2 319
matched on a request component the target does not have 78 65 561 65
part of a chain, and the target cannot require all of it 128 128 128 128
not a rule: it changes another rule 54 54 54 54
it refuses ordinary traffic once converted 10 16 8
longer than the target accepts 16
its severity is below what refuses, and the target cannot only record 1 8
it records and does not refuse 1 1 1

What a written rule loses, in how many of them:

Loss Nginx Apache (ModSecurity) Traefik HAProxy
matched on other variables than the rule names 153 156 3 160
transformations the rule was written to run after are not applied 122 112 2 111

The verdict for every rule and target is in coverage.json, attached to this release. How to read it.

Verify

This release is 2026-10-01-crs-v4.29.0-2, and it stays: releases are never deleted or replaced, so a link to this tag is a link to these files. Every file in it is signed by the workflow that built it, and attested. SHA256SUMS lists their hashes and is signed with the rest.

cosign verify-blob --bundle nginx_waf.zip.sigstore.json \
  --certificate-identity https://github.com/fabriziosalmi/patterns/.github/workflows/update_patterns.yml@refs/heads/main \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com nginx_waf.zip

Every step, and how to pin to a release.

SHA-256

bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755  nginx_waf.zip
4e23ed6afc53010490f184cfb89f51d740ce638972456cf14c0f53201f2e0dae  apache_waf.zip
3aa6837f5ba8670a40ab0816428aa1a49027dab386ccc23b7e4d5c215c99a6b9  traefik_waf.zip
ac5576818becdc5eaa8d8370f0379e6d6375371d551ef82f5ee64911d2ddb7ee  haproxy_waf.zip
echo "bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755  nginx_waf.zip" | sha256sum -c -

Documentation · Source · Issues

Don't miss a new patterns release

NewReleases is sending notifications on new releases.