Skip to main content

Vendor/product archive

openresty / lua-nginx-module CVEs

Beta · best-effort

2 CVEs tagged to openresty / lua-nginx-module0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-33452

Published Apr 22, 2025

An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36309

Published Apr 6, 2021

ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1