Patterns build · 2026-10-02
OWASP Core Rule Set coreruleset/coreruleset@v4.29.0 converted into native WAF rules for four web servers. Generated automatically; no manual edits.
Coverage: 749 patterns across 22 categories — SQLi, XSS, RCE, LFI, RFI, plus generic anomaly and protocol-violation rules.
What changed since the previous release
No rule changed since the previous release (CRS v4.29.0).
The whole of it, per rule and per target, is in changes.json, attached to this release.
Backends
| Backend | Format | Bots | Archive | Size |
|---|---|---|---|---|
| Nginx | map + if
| 1868 | nginx_waf.zip
| 52K |
| Apache | ModSecurity | 1868 | apache_waf.zip
| 84K |
| Traefik | Middleware TOML | 1868 | traefik_waf.zip
| 24K |
| HAProxy | Pattern files | 1868 | haproxy_waf.zip
| 80K |
| Envoy | RBAC filter | 1868 | envoy_waf.zip
| 88K |
Quick install
curl -LO https://github.com/fabriziosalmi/patterns/releases/download/2026-10-02-crs-v4.29.0/nginx_waf.zip
unzip nginx_waf.zip -d /etc/nginx/waf_patternsIntegration guides → Nginx · Apache · Traefik · HAProxy · Envoy
What each target does with each rule
Of the 749 records in the CRS v4.29.0 intermediate representation, what each target does:
| Target | Full | Approximate | Unsound | Dropped |
|---|---|---|---|---|
| Nginx | 11 | 159 | 0 | 579 |
| Apache (ModSecurity) | 8 | 172 | 0 | 569 |
| Traefik | 1 | 4 | 0 | 744 |
| HAProxy | 7 | 173 | 0 | 569 |
| Envoy | 7 | 177 | 0 | 565 |
Why a record is dropped, by the first reason the backend found:
| Reason | Nginx | Apache (ModSecurity) | Traefik | HAProxy | Envoy |
|---|---|---|---|---|---|
| an operator the backend cannot express | 292 | 292 | 292 | 292 | |
| matched on a request component the target does not have | 78 | 78 | 561 | 78 | 78 |
| part of a chain, and the target cannot require all of it | 128 | 128 | 128 | 128 | 128 |
| not a rule: it changes another rule | 54 | 54 | 54 | 54 | 54 |
| it refuses ordinary traffic once converted | 10 | 16 | 8 | 4 | |
| its severity is below what refuses, and the target cannot only record | 1 | 8 | 8 | ||
| longer than the target accepts | 16 | ||||
| it records and does not refuse | 1 | 1 | 1 | 1 |
What a written rule loses, in how many of them:
| Loss | Nginx | Apache (ModSecurity) | Traefik | HAProxy | Envoy |
|---|---|---|---|---|---|
| matched on other variables than the rule names | 153 | 167 | 4 | 173 | 177 |
| transformations the rule was written to run after are not applied | 122 | 122 | 3 | 121 | 125 |
The verdict for every rule and target is in coverage.json, attached to this release. How to read it.
Verify
This release is 2026-10-02-crs-v4.29.0, and it stays: releases are never deleted or replaced, so a link to this tag is a link to these files. Every file in it is signed by the workflow that built it, and attested. SHA256SUMS lists their hashes and is signed with the rest.
cosign verify-blob --bundle nginx_waf.zip.sigstore.json \
--certificate-identity https://github.com/fabriziosalmi/patterns/.github/workflows/update_patterns.yml@refs/heads/main \
--certificate-oidc-issuer https://token.actions.githubusercontent.com nginx_waf.zipEvery step, and how to pin to a release.
SHA-256
bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755 nginx_waf.zip
0c857548c4c07ffc544af86171ad6ab7a2b28f981543ad62202a57adf63bee89 apache_waf.zip
a2dca6c97ab28c64fb21f3d346c58cda65284786d78dc93152cfeca9738db64d traefik_waf.zip
1a89595c91adb137ce4553e61d7904a3ee1583dc7043aa773dc919e0566f2bc1 haproxy_waf.zip
f5d45a8abbb33c5092a98dd1bdd8f69d1be781e559f86f2b6664d9c2caed4816 envoy_waf.zip
echo "bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755 nginx_waf.zip" | sha256sum -c -