Blog post

Cloudflare or Coraza? Picking a WAF in 2026

Cloudflare's managed WAF is zero-ops but its OWASP ruleset still runs CRS 3.3; self-hosted Coraza gives you current CRS 4 and control.

Split-screen infographic comparing a managed cloud web application firewall with shields and servers against a self-hosted on-premise server rack and appliance.

A 2026 WAF choice decides who owns edge, rules, and maintenance.

Cloudflare is the zero-operations option: its managed WAF runs at the edge, hides the origin, and receives frequent updates. The trade-off is dependency on a third-party network: proxied traffic is decrypted at Cloudflare, and regional processing controls are an Enterprise add-on. Its OWASP Core Ruleset still uses the CRS 3.3.0 scoring model.

Coraza is an Apache-2.0 Go WAF for your infrastructure, available as a library, middleware, reverse proxy, or container. It is 100% compatible with OWASP CRS 4 (current release 4.29.0), while CRS 3.3.x support ends in Q3 2026. You control TLS and data flow, but must patch the engine, update rules, tune false positives, and operate the connector. Caddy is stable; nginx and Apache integrations remain experimental.

Choose Cloudflare for small teams, global audiences, or zero-ops. Choose Coraza for data sovereignty, CRS 4, or infrastructure control. Test traffic in detection mode first, record changes, and keep a rollback path.

Sources: Cloudflare OWASP ruleset, Coraza.

Related areas

These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.

Continue reading

Based on shared categories first, then the strongest overlap in tags.