Library · Open source
SecLang Engine
A ModSecurity-compatible WAF library for the JVM.
An enterprise-grade, high-performance implementation of the ModSecurity SecLang language in Scala, passing 100% of the OWASP CRS v4 regression tests. The engine behind our threat protection.
- Stars
- 1
- Language
- Java
- License
- Apache-2.0
- Last update
- 2 days ago
// build.sbt
libraryDependencies += "com.cloud-apim" %% "seclang-engine" % "2.5.1"
// the OWASP Core Rule Set as an embeddable preset
libraryDependencies += "com.cloud-apim" %% "seclang-engine-coreruleset" % "2.5.1"Features
What's inside
100% OWASP CRS v4
Passes the whole OWASP Core Rule Set v4 regression test suite.
JVM-native
No WASM, no native bindings. Pure Scala, cross-built for Scala 2.12, 2.13 and 3, with a Java DSL.
Multi-tenant by design
Presets and factories to run many rule sets side by side efficiently.
Pluggable
Host-pluggable geolocation and DNS blocklists, body processors for URL-encoded, multipart, XML and JSON.
From WASM to pure Scala
A WAF engine
you can embed anywhere.
SecLang Engine implements the ModSecurity rule language as a library: compile rules once, evaluate requests and responses from any JVM application, and get a disposition back.
It powers the Threat Protection suite for Otoroshi and WebShield. Read the story behind it on our blog: Building a JVM-native WAF: a journey from WASM to pure Scala.
The companion seclang-engine-coreruleset library packages the OWASP Core Rule Set v4 as a preset you can import with a single line.
More open-source projects
Run it in productionwithout running Otoroshi.
Our extensions are available on Otoroshi Managed, fully operated by the people that wrote them. Or get professional support for your own clusters.

