github fabriziosalmi/patterns 2026-10-02-crs-v4.29.0
WAF rules 2026-10-02-crs-v4.29.0

2 hours ago

Patterns build · 2026-10-02

OWASP Core Rule Set coreruleset/coreruleset@v4.29.0 converted into native WAF rules for four web servers. Generated automatically; no manual edits.

Coverage: 749 patterns across 22 categories — SQLi, XSS, RCE, LFI, RFI, plus generic anomaly and protocol-violation rules.

What changed since the previous release

No rule changed since the previous release (CRS v4.29.0).

The whole of it, per rule and per target, is in changes.json, attached to this release.

Backends

Backend Format Bots Archive Size
Nginx map + if 1868 nginx_waf.zip 52K
Apache ModSecurity 1868 apache_waf.zip 84K
Traefik Middleware TOML 1868 traefik_waf.zip 24K
HAProxy Pattern files 1868 haproxy_waf.zip 80K
Envoy RBAC filter 1868 envoy_waf.zip 88K

Quick install

curl -LO https://github.com/fabriziosalmi/patterns/releases/download/2026-10-02-crs-v4.29.0/nginx_waf.zip
unzip nginx_waf.zip -d /etc/nginx/waf_patterns

Integration guides → Nginx · Apache · Traefik · HAProxy · Envoy

What each target does with each rule

Of the 749 records in the CRS v4.29.0 intermediate representation, what each target does:

Target Full Approximate Unsound Dropped
Nginx 11 159 0 579
Apache (ModSecurity) 8 172 0 569
Traefik 1 4 0 744
HAProxy 7 173 0 569
Envoy 7 177 0 565

Why a record is dropped, by the first reason the backend found:

Reason Nginx Apache (ModSecurity) Traefik HAProxy Envoy
an operator the backend cannot express 292 292 292 292
matched on a request component the target does not have 78 78 561 78 78
part of a chain, and the target cannot require all of it 128 128 128 128 128
not a rule: it changes another rule 54 54 54 54 54
it refuses ordinary traffic once converted 10 16 8 4
its severity is below what refuses, and the target cannot only record 1 8 8
longer than the target accepts 16
it records and does not refuse 1 1 1 1

What a written rule loses, in how many of them:

Loss Nginx Apache (ModSecurity) Traefik HAProxy Envoy
matched on other variables than the rule names 153 167 4 173 177
transformations the rule was written to run after are not applied 122 122 3 121 125

The verdict for every rule and target is in coverage.json, attached to this release. How to read it.

Verify

This release is 2026-10-02-crs-v4.29.0, and it stays: releases are never deleted or replaced, so a link to this tag is a link to these files. Every file in it is signed by the workflow that built it, and attested. SHA256SUMS lists their hashes and is signed with the rest.

cosign verify-blob --bundle nginx_waf.zip.sigstore.json \
  --certificate-identity https://github.com/fabriziosalmi/patterns/.github/workflows/update_patterns.yml@refs/heads/main \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com nginx_waf.zip

Every step, and how to pin to a release.

SHA-256

bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755  nginx_waf.zip
0c857548c4c07ffc544af86171ad6ab7a2b28f981543ad62202a57adf63bee89  apache_waf.zip
a2dca6c97ab28c64fb21f3d346c58cda65284786d78dc93152cfeca9738db64d  traefik_waf.zip
1a89595c91adb137ce4553e61d7904a3ee1583dc7043aa773dc919e0566f2bc1  haproxy_waf.zip
f5d45a8abbb33c5092a98dd1bdd8f69d1be781e559f86f2b6664d9c2caed4816  envoy_waf.zip
echo "bd2730d9e9be2d10a6f773280ba7ed9c39ba6fe94f606d79a90bc267327a6755  nginx_waf.zip" | sha256sum -c -

Documentation · Source · Issues

Don't miss a new patterns release

NewReleases is sending notifications on new releases.