Description
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LExploitability: 2.2 | Impact: 5.5Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: Low
Affected Packages2 packages
🔴Vulnerability Details
3CVEListCVE-2024-33452: An issue in OpenResty lua-nginx-module v↗2025-04-22 ▶ GHSAGHSA-qm42-2jf7-gc6x: An issue in OpenResty lua-nginx-module v↗2025-04-22 ▶ OSVCVE-2024-33452: An issue in OpenResty lua-nginx-module v↗2025-04-22 ▶ 📋Vendor Advisories
2Red Hatlua-nginx-module: HTTP request smuggling via a crafted HEAD request↗2025-04-22 ▶ DebianCVE-2024-33452: libnginx-mod-http-lua - An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote atta...↗2024 ▶