Patterns build · 2026-10-01
OWASP Core Rule Set coreruleset/coreruleset@v4.29.0 converted into native WAF rules for four web servers. Generated automatically; no manual edits.
Coverage: 749 patterns across 22 categories — SQLi, XSS, RCE, LFI, RFI, plus generic anomaly and protocol-violation rules.
What changed since the previous release
No rule changed since the previous release (CRS v4.29.0).
The whole of it, per rule and per target, is in changes.json, attached to this release.
Backends
| Backend | Format | Bots | Archive | Size |
|---|---|---|---|---|
| Nginx | map + if
| 1868 | nginx_waf.zip
| 52K |
| Apache | ModSecurity | 1868 | apache_waf.zip
| 68K |
| Traefik | Middleware TOML | 1868 | traefik_waf.zip
| 20K |
| HAProxy | Pattern files | 1868 | haproxy_waf.zip
| 60K |
Quick install
curl -LO https://github.com/fabriziosalmi/patterns/releases/download/2026-10-01-crs-v4.29.0-2/nginx_waf.zip
unzip nginx_waf.zip -d /etc/nginx/waf_patternsIntegration guides → Nginx · Apache · Traefik · HAProxy
What each target does with each rule
Of the 749 records in the CRS v4.29.0 intermediate representation, what each target does:
| Target | Full | Approximate | Unsound | Dropped |
|---|---|---|---|---|
| Nginx | 11 | 159 | 0 | 579 |
| Apache (ModSecurity) | 7 | 159 | 0 | 583 |
| Traefik | 0 | 3 | 0 | 746 |
| HAProxy | 6 | 160 | 0 | 583 |
Why a record is dropped, by the first reason the backend found:
| Reason | Nginx | Apache (ModSecurity) | Traefik | HAProxy |
|---|---|---|---|---|
| an operator the backend cannot express | 292 | 319 | 2 | 319 |
| matched on a request component the target does not have | 78 | 65 | 561 | 65 |
| part of a chain, and the target cannot require all of it | 128 | 128 | 128 | 128 |
| not a rule: it changes another rule | 54 | 54 | 54 | 54 |
| it refuses ordinary traffic once converted | 10 | 16 | 8 | |
| longer than the target accepts | 16 | |||
| its severity is below what refuses, and the target cannot only record | 1 | 8 | ||
| it records and does not refuse | 1 | 1 | 1 |
What a written rule loses, in how many of them:
| Loss | Nginx | Apache (ModSecurity) | Traefik | HAProxy |
|---|---|---|---|---|
| matched on other variables than the rule names | 153 | 156 | 3 | 160 |
| transformations the rule was written to run after are not applied | 122 | 112 | 2 | 111 |
The verdict for every rule and target is in coverage.json, attached to this release. How to read it.
Verify
This release is 2026-10-01-crs-v4.29.0-2, and it stays: releases are never deleted or replaced, so a link to this tag is a link to these files. Every file in it is signed by the workflow that built it, and attested. SHA256SUMS lists their hashes and is signed with the rest.
cosign verify-blob --bundle nginx_waf.zip.sigstore.json \
--certificate-identity https://github.com/fabriziosalmi/patterns/.github/workflows/update_patterns.yml@refs/heads/main \
--certificate-oidc-issuer https://token.actions.githubusercontent.com nginx_waf.zipEvery step, and how to pin to a release.
SHA-256
bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755 nginx_waf.zip
4e23ed6afc53010490f184cfb89f51d740ce638972456cf14c0f53201f2e0dae apache_waf.zip
3aa6837f5ba8670a40ab0816428aa1a49027dab386ccc23b7e4d5c215c99a6b9 traefik_waf.zip
ac5576818becdc5eaa8d8370f0379e6d6375371d551ef82f5ee64911d2ddb7ee haproxy_waf.zip
echo "bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755 nginx_waf.zip" | sha256sum -c -