CVE-2024-33452
published 2025-04-22CVE-2024-33452: An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
PriorityP348high7.7CVSS 3.1
AVNACHPRNUINSUCHIHAL
EPSS
0.72%
49.8th percentile
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnginx-mod-http-lua | < libnginx-mod-http-lua 1:0.10.23-1+deb12u1 (bookworm) | libnginx-mod-http-lua 1:0.10.23-1+deb12u1 (bookworm) |
| debian | nginx | < libnginx-mod-http-lua 1:0.10.23-1+deb12u1 (bookworm) | libnginx-mod-http-lua 1:0.10.23-1+deb12u1 (bookworm) |
| f5 | nginx | >= 0 < 1.18.0-6.1+deb11u5 | 1.18.0-6.1+deb11u5 |
| f5 | nginx | >= 0 < 1.22.0-3 | 1.22.0-3 |
| f5 | nginx | >= 0 < 1.22.0-3 | 1.22.0-3 |
| f5 | nginx | >= 0 < 1.22.0-3 | 1.22.0-3 |
| openresty | lua-nginx-module | <= 0.10.26 | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
osv7.7HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
lua-nginx-module: HTTP request smuggling via a crafted HEAD request
vendor_redhat·2025-04-22·CVSS 7.7
CVE-2024-33452 [HIGH] CWE-444 lua-nginx-module: HTTP request smuggling via a crafted HEAD request
lua-nginx-module: HTTP request smuggling via a crafted HEAD request
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
A flaw was found in the OpenResty lua-nginx-module. Affected versions of this component allow a remote attacker to conduct HTTP request smuggling via a crafted HEAD request. The attacker can use this attack to bypass any frontend proxy protection, serve malicious responses to all the users in the same connection pool, and capture the responses of other users.
Statement: This vulnerability marked as Important not just a Moderate flaw, because it enables a class of HTTP Request Smuggling attacks that bypass normal security boundaries between front-end and back-end components. W
Debian
CVE-2024-33452: libnginx-mod-http-lua - An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote atta...
vendor_debian·2024·CVSS 7.7
CVE-2024-33452 [HIGH] CVE-2024-33452: libnginx-mod-http-lua - An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote atta...
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
Scope: local
bookworm: resolved (fixed in 1:0.10.23-1+deb12u1)
forky: resolved (fixed in 1:0.10.27-1)
sid: resolved (fixed in 1:0.10.27-1)
trixie: resolved (fixed in 1:0.10.27-1)
GHSA
GHSA-qm42-2jf7-gc6x: An issue in OpenResty lua-nginx-module v
ghsa_unreviewed·2025-04-22
CVE-2024-33452 [HIGH] CWE-444 GHSA-qm42-2jf7-gc6x: An issue in OpenResty lua-nginx-module v
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
OSV
CVE-2024-33452: An issue in OpenResty lua-nginx-module v
osv·2025-04-22·CVSS 7.7
CVE-2024-33452 [HIGH] CVE-2024-33452: An issue in OpenResty lua-nginx-module v
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-22
Published