Skip to main content

Vendor archive

openresty CVEs

Beta · best-effort

7 CVEs tagged to vendor openresty1 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-55233

Published Jul 10, 2026

OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-33452

Published Apr 22, 2025

An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39702

Published Jul 23, 2024

In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker co…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36309

Published Apr 6, 2021

ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9230

Published Apr 2, 2018

In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, whic…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1